216.73.217.22

A new playground: Malicious campaigns proliferate from VSCode to npm

· Published 19/12/2024 04:01 · Modified 19/12/2024 13:39

Export JSON

Essential information

Published
19/12/2024 04:01
Modified
19/12/2024 13:39
Tags
2024-12-19 crypto downloader malicious extensions npm obfuscation software supply chain vscode zoom
Related entities
2 observables

Description

This intelligence details the emergence of malicious campaigns spreading from to . Researchers observed an increasing amount of malicious activity in Marketplace, with threat actors using packages to inject malicious code into IDE. The campaign initially targeted the community but later expanded to impersonate the application. contained functionality and were obfuscated with Javascript Obfuscator. The campaign then spread to with the package 'etherscancontracthandler'. The analysis highlights the importance of scrutinizing open source, third-party, and commercial code, as well as performing regular security assessments to prevent IDE compromises and protect the .

External references