1. Request malware
2. Download malware
3. Make malware executable
4. Run malware
This is the extent of the extension available in the VS Marketplace. Installs a Mythic agent from the C2.
1. Request malware
2. Download malware
3. Make malware executable
4. Run malware
This is the extent of the extension available in the VS Marketplace. Installs a Mythic agent from the C2.
... uses Open VSX for extensions and shows malicious listings to users.
... uses Open VSX for extensions and shows malicious listings to users.
This 'theme' downloads a malicious zip, unpacks it, and runs it silently with PowerShell.
This 'theme' downloads a malicious zip, unpacks it, and runs it silently with PowerShell.
secureannex.com/blog/glasswo...
secureannex.com/blog/glasswo...
tailwind-nuxt.tailwindcss-for-react
flutcode.flutter-extension
yamlcode.yaml-vscode-extension
tailwind-nuxt.tailwindcss-for-react
flutcode.flutter-extension
yamlcode.yaml-vscode-extension
VS Marketplace:
iconkieftwo.icon-theme-materiall
1/3
VS Marketplace:
iconkieftwo.icon-theme-materiall
1/3
m.youtube.com/watch?v=FiJ_...
m.youtube.com/watch?v=FiJ_...
This compares past code with additional context to understand how an extension is changing over time. Catch bad quick!
This compares past code with additional context to understand how an extension is changing over time. Catch bad quick!
Nope - completely manipulated stats and it doesn't even contain real code. It exists only to collect your searches and earn Bing Rewards.
Nope - completely manipulated stats and it doesn't even contain real code. It exists only to collect your searches and earn Bing Rewards.
Are you using this feature?
Are you using this feature?
secureannex.com/blog/ransomv...
secureannex.com/blog/ransomv...
-Valid accounts still rule the day for initial access
-Open VSX rotate leaked creds
-ZeroAccess botnet dev is now a software dev
-BadCandy flourishes in Australia
-New Katreus miner
-Malware reports on Aura Stealer, SectopRAT, SleepyDuck RAT, OysterLoader
-Valid accounts still rule the day for initial access
-Open VSX rotate leaked creds
-ZeroAccess botnet dev is now a software dev
-BadCandy flourishes in Australia
-New Katreus miner
-Malware reports on Aura Stealer, SectopRAT, SleepyDuck RAT, OysterLoader