216.73.216.36

VS Code extensions contain trojan-laden fake image

· Published 11/12/2025 12:06 · Modified 21/12/2025 18:58

Export JSON

Essential information

Published
11/12/2025 12:06
Modified
21/12/2025 18:58
Tags
2025-12-11 npm rust trojan vs code
Related entities
8 techniques (mitre), 1 malware

Description

A malicious campaign involving 19 Visual Studio Code extensions has been uncovered, hiding malware in dependency folders. Active since February 2025, the campaign abuses a legitimate package to avoid detection and crafts an archive containing malicious binaries disguised as a PNG image. The attackers modified the popular 'path-is-absolute' package, adding malicious files that are only present when installed through the compromised extensions. The malware is activated when starts, decoding a JavaScript dropper and executing two malicious binaries using a living-off-the-land binary. This sophisticated attack demonstrates the evolving techniques of threat actors, targeting the Marketplace and exploiting trusted components to evade detection.

External references