VS Code extensions contain trojan-laden fake image
Essential information
- Published
- 11/12/2025 12:06
- Modified
- 21/12/2025 18:58
- Tags
- 2025-12-11 npm rust trojan vs code
- Related entities
- 8 techniques (mitre), 1 malware
Description
A malicious campaign involving 19 Visual Studio Code extensions has been uncovered, hiding malware in dependency folders. Active since February 2025, the campaign abuses a legitimate npm package to avoid detection and crafts an archive containing malicious binaries disguised as a PNG image. The attackers modified the popular 'path-is-absolute' package, adding malicious files that are only present when installed through the compromised extensions. The malware is activated when VS Code starts, decoding a JavaScript dropper and executing two malicious binaries using a living-off-the-land binary. This sophisticated attack demonstrates the evolving techniques of threat actors, targeting the VS Code Marketplace and exploiting trusted components to evade detection.