Malicious VSCode Marketplace extensions hid trojan in fake PNG file

Malicious VSCode Marketplace extensions hid trojan in fake PNG file

A malicious campaign involving 19 VSCode extensions exploited the platform by hiding malware within dependency folders, with malicious code embedded in popular npm packages like β€˜path-is-absolute.’ Security researchers found these extensions used obfuscated scripts and hosted dangerous binaries, prompting Microsoft to remove them. #VSCodeExtensions #SupplyChainAttacks

Keypoints

  • Threat actors targeted VSCode marketplace with malicious extensions since February.
  • The attackers embedded malware in dependency folders to evade detection.
  • They used popular npm packages like β€˜path-is-absolute’ to hide malicious code.
  • The malicious payload included a decodable JavaScript dropper and harmful binaries disguised as images.
  • Microsoft removed all affected extensions, but users should scan their systems for compromises.

Read More: https://www.bleepingcomputer.com/news/security/malicious-vscode-marketplace-extensions-hid-trojan-in-fake-png-file/