HomeSecurityMalicious VSCode extensions target crypto developers and investors

Malicious VSCode extensions target crypto developers and investors

Researchers have discovered malicious Visual Studio Code (VSCode) extensions that download obfuscated PowerShell payloads to target developers and cryptocurrency projects as part of supply chain attacks.

VSCode extensions developers crypto

Researchers at Reversing Labs reported that the malicious extensions first appeared in the VSCode marketplace in October.

“The community was first informed about this campaignin early October and since then, the team has been monitoring it steadily.“.

An additional package targeting the crypto community and part of this campaign was found on NPM.

See also: Fake Bitwarden ads on Facebook push information-stealing Chrome extension

Malicious Visual Studio Code (VSCode) extensions

The campaign includes 18 malicious extensions that primarily target crypto investors and those looking for productivity tools like Zoom.

Researchers identified the following extensions in the VSCode Marketplace:

  • EVM.Blockchain-Toolkit
  • VoiceMod.VoiceMod
  • ZoomVideoCommunications.Zoom
  • ZoomINC.Zoom-Workplace
  • Ethereum.SoliditySupport
  • ZoomWorkspace.Zoom (3 versions)
  • ethereumorg.Solidity-Language-for-Ethereum
  • VitalikButerin.Solidity-Ethereum (two versions)
  • SolidityFoundation.Solidity-Ethereum
  • EthereumFoundation.Solidity-Language-for-Ethereum (2 versions)
  • SOLIDITY.Solidity-Language
  • GavinWood.SolidityLang (2 versions)
  • EthereumFoundation.Solidity-for-Ethereum-Language

On npm, the attackers uploaded five versions of the 'etherscancontacthandler' package, which were collectively downloaded 350 times.

To increase the apparent legitimacy of the packages, the attackers added fake reviews and artificially increased the number of installs.

See also: Kimsuky hackers use malicious Chrome extension to steal credentials

ReversingLabs says that all of the malicious VSCode extensions had the same functionality and were designed to download obfuscated second-stage payloads from suspicious domains.

Two of the malicious domains chosen to give a sense of legitimacy are “microsoft-visualstudiocode[.]com” and “captchacdn[.]com”, while others used TLDs such as “.lat” and “.ru”.

At present, the second-stage payloads have not been analyzed, so its functions are unknown.

According to BleepingComputer, the secondary payloads received by these malicious VSCode extensions are obfuscated Windows CMD files that launch a hidden PowerShell command. This command decrypts strings (encrypted with AES) in additional CMD files to install further malicious payloads on the compromised system and execute them.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Malicious VSCode extensions target crypto developers and investors

The researchers provided a list of malicious packages and VSCode extensions with their SHA1 hashes at the bottom of their report.

See also: Malicious SharePoint notifications distribute Xloader Malware

The discovery of malicious VSCode extensions is a stark reminder of the ongoing threat of cyberattacks to the developer and crypto communities. As the demand for third-party tools and libraries continues to grow, it is important for developers to take the necessary precautions to protect their environment and data from potential attackers. This includes regularly checking the source and reviews of extensions used in their development environment. By staying vigilant, implementing secure coding practices, and regularly performing vulnerability assessments, developers can better defend themselves.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS