Malware, Threat Intelligence

Trojan concealed by illicit VSCode extensions in bogus PNGs

Trojan malware

HackRead reports that fake PNG files have been harnessed to obscure trojans across 19 malicious VSCode extensions as part of an advanced attack campaign that has been underway since February.

Threat actors behind the operation have tampered the widely used "path-is-absolute" dependency with illicit code that decodes a hidden JavaScript dropper in the "lock" file immediately after VSCode startup to reduce suspicion among its users, according to ReversingLabs researchers.

Such a dropper then enables the execution of a pair of nefarious binaries within the "banner.png" file, one of which is a trojan whose capabilities remain a mystery. Other extensions were also discovered to have leveraged the "@actions/io" dependency instead, with binaries separated into .ts and .map files rather than being installed in a bogus PNG file, said researchers, who called on developers to conduct more stringent extension reviews prior to installation.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds