Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hidden Malware in Open VSX Extension Threatens Developers

Hidden Malware in Open VSX Extension Threatens Developers

Posted on March 19, 2026 By CWS

A recent cybersecurity incident has uncovered a malicious payload within a widely used code editor extension listed on the Open VSX registry. This extension, named fast-draft under the KhangNghiem publisher, secretly deployed a remote access trojan (RAT) and an information-stealing software onto developer systems, going unnoticed until recently.

Discovery and Spread of Malicious Versions

The compromised extension had amassed over 26,000 downloads before the hidden threats embedded within specific versions were identified. Versions 0.10.89, 0.10.105, 0.10.106, and 0.10.112 were found to contain harmful code that interacted with a malicious GitHub repository operated by an entity known as BlokTrooper.

These versions fetched shell scripts from the repository at raw.githubusercontent[.]com/BlokTrooper/extension, executing them directly on the affected systems. This led to the deployment and execution of a more comprehensive malware payload. Notably, other versions like 0.10.88, 0.10.111, and 0.10.135 did not exhibit such behavior, indicating a likely breach of the publisher’s release credentials.

Analysis of the Attack’s Impact

Security experts from Aikido carried out a detailed review of the fast-draft version history, uncovering the malicious activity. Despite notifying the extension’s maintainer on March 12, 2026, via a public GitHub issue, no response was recorded at the time of reporting.

The consequences of this breach are severe. Developers with compromised versions installed inadvertently permitted attackers to gain complete control over their systems. The malware’s secondary payload executed multiple attack modules simultaneously, targeting browser credentials, cryptocurrency wallets, local files, source code, and clipboard contents.

Technical Overview of the Second-Stage Attack

Upon execution, the malware downloaded a ZIP file, extracted it, and launched several Node.js processes, each focusing on different attack vectors. The first module provided attackers with real-time control over the victim’s device, while the second targeted browsers like Chrome and Edge, extracting saved passwords and cryptocurrency wallet data.

A third module scanned user directories for sensitive documents and source codes, bypassing known AI-assisted development environments. The final component monitored clipboard data, capturing and transmitting sensitive information like seed phrases and API keys to the attacker’s server.

Developers are advised to check for and remove any affected versions of fast-draft immediately. It is crucial to rotate all credentials and keys stored on impacted systems. Network administrators should block traffic to the IP 195[.]201[.]104[.]53 and monitor for any suspicious activity linked to BlokTrooper’s GitHub repository.

Cyber Security News Tags:BlokTrooper, browser credential theft, code editor, cryptocurrency theft, Cybersecurity, developer security, GitHub, InfoStealer, Malware, network security, Node.js malware, Open VSX, RAT, source code security, supply chain attack

Post navigation

Previous Post: Cisco Firewall Flaw Exploited in Ransomware Attacks
Next Post: DarkSword iOS Kit Exploits Multiple Flaws for Device Control

Related Posts

Top 5 Best Cybersecurity Companies Leading The Industry Right Now in 2025 Top 5 Best Cybersecurity Companies Leading The Industry Right Now in 2025 Cyber Security News
Phishing Threat Targets Signal Users for Backup Access Phishing Threat Targets Signal Users for Backup Access Cyber Security News
Rockstar Data Breach: 78.6 Million Records Exposed Rockstar Data Breach: 78.6 Million Records Exposed Cyber Security News
Popular Chrome Extension with Over 6 Million Installs Captures User Inputs to AI Chatbots Popular Chrome Extension with Over 6 Million Installs Captures User Inputs to AI Chatbots Cyber Security News
Critical Flaw in Canon MailSuite Risks RCE Attacks Critical Flaw in Canon MailSuite Risks RCE Attacks Cyber Security News
kkRAT Employs Network Communication Protocol to Steal Clipboard Contents kkRAT Employs Network Communication Protocol to Steal Clipboard Contents Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerabilities Patched by Atlassian and Splunk
  • PCI DSS Compliance: Checkout Page Scripts Under Scrutiny
  • Critical HTTP/2 Vulnerability in Apache Threatens Servers
  • Cisco Fixes Critical Security Flaw in Identity Services
  • SailPoint Plans Entro Acquisition for Enhanced Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerabilities Patched by Atlassian and Splunk
  • PCI DSS Compliance: Checkout Page Scripts Under Scrutiny
  • Critical HTTP/2 Vulnerability in Apache Threatens Servers
  • Cisco Fixes Critical Security Flaw in Identity Services
  • SailPoint Plans Entro Acquisition for Enhanced Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark