Malicious VSCode Marketplace extensions hid trojan in fake PNG file
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。首先,我需要通读整篇文章,抓住主要信息。 文章讲的是一个恶意活动,通过VSCode Marketplace上的19个扩展传播。这些扩展隐藏了恶意软件在依赖文件夹里。攻击者用了伪装成PNG图片的恶意文件。ReversingLabs发现这些扩展预装了node_modules文件夹,阻止VSCode从npm获取依赖。攻击者修改了常用包如path-is-absolute,并添加了一个类在index.js里自动执行。这导致解码了一个JavaScript加载器,并释放了恶意二进制文件,包括cmstp.exe和一个Rust木马。微软已经移除了这些扩展,但用户仍需检查系统。 现在,我需要把这些信息浓缩到100字以内。要涵盖攻击手段、目标、发现过程和影响。可能的结构是:恶意活动通过VSCode扩展传播,隐藏依赖中,伪装成图片文件,利用常用包植入代码,释放恶意软件,已移除但需检查。 这样应该能准确传达主要内容,同时符合字数限制。 </think> 恶意活动通过VSCode Marketplace上的19个扩展传播,隐藏恶意软件于依赖文件夹中,并伪装成.PNG图像。攻击者利用常用npm包植入代码,在VSCode启动时执行恶意操作并释放木马程序。 2025-12-11 21:0:24 Author: www.bleepingcomputer.com(查看原文) 阅读量:8 收藏

Malicious VSCode Marketplace extensions hid trojan in fake PNG file

A stealthy campaign with 19 extensions on the VSCode Marketplace has been active since February, targeting developers with malware hidden inside dependency folders.

The malicious activity was uncovered recently, and security researchers found that the operator used a malicious file posing as a .PNG image.

The VSCode Market is Microsoft’s official extensions portal for the widely used VSCode integrated development environment (IDE), allowing developers to extend its functionality or add visual customizations.

Due to its popularity and potential for high-impact supply-chain attacks, the platform is constantly targeted by threat actors with evolving campaigns.

ReversingLabs, a company specializing in file and software supply-chain security, found that the malicious extensions come pre-packaged with a ‘node_modules’ folder to prevent VSCode from fetching dependencies from the npm registry when installing them.

Inside the bundled folder, the attacker added a modified dependency, ‘path-is-absolute’ or ‘@actions/io,’ with an additional class in the ‘index.js’ file that executes automatically when starting the VSCode IDE.

Malicious code added to the index.js file
Malicious code added to the index.js file
Source: ReversingLabs

It should be noted that ‘path-is-absolute’ is a massively popular npm package with 9 billion downloads since 2021, and the weaponized version existed only in the 19 extensions used in the campaign.

The code introduced by the new class in the ‘index.js’ file decodes an obfuscated JavaScript dropper inside a file named 'lock'. Another file present in the dependencies folder is an archive posing as a .PNG (banner.png) file that hosts two malicious binaries: a living-off-the-land binary (LoLBin) called 'cmstp.exe' and a Rust-based trojan.

ReversingLabs is still analyzing the trojan to determine its full capabilities.

According to the researchers, the 19 VSCode extensions in the campaign use variations of the following names, all published with the version number 1.0.0:

  • Malkolm Theme
  • PandaExpress Theme
  • Prada 555 Theme
  • Priskinski Theme

ReversingLabs reported them to Microsoft, and BleepingComputer confirmed that all of them have been removed. However, users who installed the extensions should scan their system for signs of compromise.

Because threat actors find new ways to evade detection on public repositories used for software development, it is recommended that users inspect packages before installation, especially when the source is not a reputable publisher.

They should carefully comb through dependencies, especially when they are bundled in the package, as is the case with VS Code extensions, and not pulled from a trusted source, as it happens with npm.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/malicious-vscode-marketplace-extensions-hid-trojan-in-fake-png-file/
如有侵权请联系:admin#unsafe.sh