216.73.216.6

Malicious VSCode Extension Launches Multi-Stage Attack Chain with Anivia Loader and OctoRAT

· Published 04/12/2025 10:32 · Modified 21/12/2025 18:22

Export JSON

Essential information

Published
04/12/2025 10:32
Modified
21/12/2025 18:22
Tags
2025-12-04 anivia developers extension multi-stage octorat process-hollowing remote-access-toolkit supply-chain uac bypass vscode
Related entities
8 observables, 18 techniques (mitre), 2 malware

Description

A malicious Visual Studio Code named 'prettier--plus' was discovered on the official Marketplace, impersonating the legitimate Prettier formatter. This served as the entry point for a malware chain, starting with the loader, which decrypted and executed further payloads in memory. The final stage, , is a comprehensive remote access toolkit providing over 70 commands for surveillance, file theft, remote desktop control, persistence, privilege escalation, and harassment. The attack chain employs sophisticated techniques like AES encryption, process hollowing, and . The threat actor's GitHub repository showed active payload rotation to evade detection. This attack highlights the evolving threats targeting and the abuse of trusted tools in their ecosystem.

External references