https://www.bleepingcomputer.com/news/security/malicious-vscode-marketplace-extensions-hid-trojan-in-fake-png-file/ BleepingComputer.com logo * * * * [ ] [Login] [Sign up] * * * * [ ] [Login] [Sign up] * News + Featured + Latest + Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws + New DroidLock malware locks Android devices and demands a ransom New DroidLock malware locks Android devices and demands a ransom + Windows PowerShell now warns when running Invoke-WebRequest scripts Windows PowerShell now warns when running Invoke-WebRequest scripts + Over 10,000 Docker Hub images found leaking credentials, auth keys Over 10,000 Docker Hub images found leaking credentials, auth keys + Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks + Notepad++ fixes flaw that let attackers push malicious update files Notepad++ fixes flaw that let attackers push malicious update files + Malicious VSCode Marketplace extensions hid trojan in fake PNG file Malicious VSCode Marketplace extensions hid trojan in fake PNG file + Enjoy Costco Gold Star Membership for a year and get $40 to use later Enjoy Costco Gold Star Membership for a year and get $40 to use later * Tutorials + Latest + Popular + How to access the Dark Web using the Tor Browser How to access the Dark Web using the Tor Browser + How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 + How to use the Windows Registry Editor How to use the Windows Registry Editor + How to backup and restore the Windows Registry How to backup and restore the Windows Registry + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Webinars * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * VPNs + Popular + Best VPNs Best VPNs + How to change IP address How to change IP address + Access the dark web safely Access the dark web safely + Best VPN for YouTube Best VPN for YouTube * Forums * More + Virus Removal Guides + Startup Database + Uninstall Database + Glossary + Send us a Tip! + Welcome Guide TheatLocker * Home * News * Security * Malicious VSCode Marketplace extensions hid trojan in fake PNG file Malicious VSCode Marketplace extensions hid trojan in fake PNG file By Bill Toulas * December 11, 2025 * 03:54 PM * 0 Malicious VSCode Marketplace extensions hid trojan in fake PNG file A stealthy campaign with 19 extensions on the VSCode Marketplace has been active since February, targeting developers with malware hidden inside dependency folders. The malicious activity was uncovered recently, and security researchers found that the operator used a malicious file posing as a .PNG image. The VSCode Market is Microsoft's official extensions portal for the widely used VSCode integrated development environment (IDE), allowing developers to extend its functionality or add visual customizations. Due to its popularity and potential for high-impact supply-chain attacks, the platform is constantly targeted by threat actors with evolving campaigns. ReversingLabs, a company specializing in file and software supply-chain security, found that the malicious extensions come pre-packaged with a 'node_modules' folder to prevent VSCode from fetching dependencies from the npm registry when installing them. Inside the bundled folder, the attacker added a modified dependency, 'path-is-absolute' or '@actions/io,' with an additional class in the 'index.js' file that executes automatically when starting the VSCode IDE. Malicious code added to the index.js fileMalicious code added to the index.js file Source: ReversingLabs It should be noted that 'path-is-absolute' is a massively popular npm package with 9 billion downloads since 2021, and the weaponized version existed only in the 19 extensions used in the campaign. The code introduced by the new class in the 'index.js' file decodes an obfuscated JavaScript dropper inside a file named 'lock'. Another file present in the dependencies folder is an archive posing as a .PNG (banner.png) file that hosts two malicious binaries: a living-off-the-land binary (LoLBin) called 'cmstp.exe' and a Rust-based trojan. ReversingLabs is still analyzing the trojan to determine its full capabilities. According to the researchers, the 19 VSCode extensions in the campaign use variations of the following names, all published with the version number 1.0.0: * Malkolm Theme * PandaExpress Theme * Prada 555 Theme * Priskinski Theme ReversingLabs reported them to Microsoft, and BleepingComputer confirmed that all of them have been removed. However, users who installed the extensions should scan their system for signs of compromise. Because threat actors find new ways to evade detection on public repositories used for software development, it is recommended that users inspect packages before installation, especially when the source is not a reputable publisher. They should carefully comb through dependencies, especially when they are bundled in the package, as is the case with VS Code extensions, and not pulled from a trusted source, as it happens with npm. tines Break down IAM silos like Bitpanda, KnowBe4, and PathAI Broken IAM isn't just an IT problem - the impact ripples across your whole business. This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy. Get the guide Related Articles: AI-Slop ransomware test sneaks on to VS Code marketplace Malicious VSCode extensions on Microsoft's registry drop infostealers Fake Solidity VSCode extension on Open VSX backdoors developers PhantomRaven attack floods npm with credential-stealing packages Self-spreading GlassWorm malware hits OpenVSX, VS Code registries * Developer * Extensions * IDE * npm * Visual Studio Code * VS Code * VSCode * * * * * Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. * Previous Article * Next Article Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] ThreatLocker Popular Stories * Microsoft Patch Tuesday Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws * Windows 10 Microsoft releases Windows 10 KB5071546 extended security update * Fortinet Fortinet warns of critical FortiCloud SSO login auth bypass flaws Sponsor Posts * Turn threat headlines into validated defense strategies with Agentic AI Turn threat headlines into validated defense strategies with Agentic AI * Manage enterprise IT hygiene with Wazuh, the open source XDR platform Manage enterprise IT hygiene with Wazuh, the open source XDR platform * Discover how elite SOCs use NDR to protect their networks Discover how elite SOCs use NDR to protect their networks * Empowering IT teams with intelligence driven cyber threat research Empowering IT teams with intelligence driven cyber threat research * What you're overlooking to protect your business What you're overlooking to protect your business Upcoming Webinar Webinar Follow us: * * * * * Main Sections * News * Webinars * VPN Buyer Guides * SysAdmin Software Guides * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2025 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT