HomeSecurityFake Moltbot AI coding assistant on VS Code Marketplace

Fake Moltbot AI coding assistant on VS Code Marketplace

Cybersecurity researchers have spotted a new malicious Microsoft Visual Studio Code (VS Code) for Moltbot (formerly Clawdbot) on the official Extensions Marketplace, which claims to be a free artificial intelligence (AI) coding assistant, but secretly distributes a malicious payload to compromised computers.

See also: North Korean hackers target developers through malicious VS Code projects

Moltbot

The extension, called “ClawdBot Agent – ​​AI Coding Assistant” (“clawdbot.clawdbot-agent”), has already been removed by Microsoft. It was posted by a user named “clawdbot” on January 27, 2026.

Moltbot has gained significant popularity, surpassing 85,000 stars on GitHub. The open-source project, created by Austrian developer Peter Steinberger, allows users to run a personal AI assistant powered by a large language model (LLM) locally on their devices and interact with it via established communication platforms such as WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage, Microsoft Teams, and WebChat.

Significantly, Moltbot does not have a legitimate extension for VS Code, which means that the malicious actors behind this activity took advantage of the tool's growing popularity to trick unsuspecting developers into installing it.

The malicious extension is designed to run automatically every time the integrated development environment (IDE) is launched, secretly retrieving a file named “config.json” from an external server (“clawdbot.getintwopc[.]site”) to execute an executable file named “Code.exe” that deploys a legitimate remote desktop program like ConnectWise ScreenConnect.

The application then connects to the URL “meeting.bulletmailer[.]net:8041“, providing the attacker with continuous remote access to the compromised computer.

See also: Evelyn stealer exploits VS Code extensions

Fake Moltbot AI coding assistant on VS Code Marketplace

“ The attackers set up their own ScreenConnect relay server, created a pre-configured client installer, and distributed it via the VS Code extension ,” said Aikido researcher Charlie Eriksen . “ When victims install the extension, they get a fully functional ScreenConnect client that immediately communicates with the attacker’s infrastructure. ”

Additionally, the extension incorporates a fallback mechanism that retrieves a DLL referenced in “config.json” and loads it to obtain the same payload from Dropbox. The DLL (“DWrite.dll”), written in Rust, ensures that the ScreenConnect client is delivered even if the command and control (C2) infrastructure becomes inaccessible.

This extension also incorporates hardcoded URLs to obtain the executable and DLL to be loaded. A second alternative method involves using a batch script to obtain the loads from a different domain (“darkgptprivate[.]com”).

The revelation comes as security researcher and Dvuln founder Jamieson O'Reilly found hundreds of unauthenticated Moltbot examples online, exposing configuration data, API keys, OAuth credentials, and chat histories from private conversations to unauthorized parties.

This opens the door to scenarios where an attacker can impersonate the operator to their contacts, insert messages into ongoing conversations, modify the agent’s responses, and extract sensitive data without their knowledge. More critically, an attacker could distribute a compromised Moltbot “capability” through MoltHub (formerly ClawdHub) to orchestrate supply chain attacks and exfiltrate sensitive data.

See also: Spring vulnerability allows commands to be executed on the user's PC

Fake Moltbot AI coding assistant on VS Code Marketplace

Intruder, in a similar analysis, noted widespread misconfigurations leading to credential exposure, prompt injection vulnerabilities, and compromised examples across multiple cloud providers.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS