At least nine malicious Visual Studio Code extensions, which have amassed more than 300,000 installations between Apr. 4 and Apr. 7, have been leveraged as part of a sweeping cryptojacking campaign, Infosecurity Magazine reports.
Installing the nefarious VS Code extensions the most prevalent of which is Discord Rich Presence published by Mark H., who is also behind six other extensions facilitates the covert execution of a Windows security-deactivating PowerShell script and scheduled tasks prior to the deployment of the XMRig cryptocurrency mining malware, an analysis from cybersecurity startup ExtensionTotal revealed. While the two other VS Code extensions were published by different users, identical coding across all of the extensions indicates a singular origin, according to ExtensionTotal researchers. "The attackers created a sophisticated multi-stage attack, even installing the legitimate extensions they impersonated to avoid raising suspicion while mining cryptocurrency in the background," said ExtensionTotal co-founder Itay Kruk, who noted the sophistication of the attack scheme.
The Hacker News disclosed that the threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
The UK's National Cyber Security Centre (NCSC) issued an alert regarding a new 'zero-click' threat campaign orchestrated by Russian state-backed hackers targeting organizations across critical sectors, according to a recent report by IT Pro.
An open-source AI assistant named Hermes was used in a cyberattack targeting Thailand's Ministry of Finance, compromising sensitive personnel data and internal systems.