Security researchers at ReversingLabs have identified a sophisticated campaign in which 19 malicious Visual Studio Code (VS Code) extensions were uploaded to the VS Code Marketplace, targeting developers by hiding a Trojan within their dependency folders. The attackers modified a widely trusted npm package, path-is-absolute, to include malicious code that executed upon VS Code startup, ultimately decoding a JavaScript dropper concealed in a file named lock. The final payload was disguised as a banner.png file, which, despite its image extension, was actually an archive containing two malicious binaries. This campaign, active since February 2025 and discovered in December, highlights the risks of supply chain attacks in developer ecosystems.
The malicious extensions either impersonated popular packages or claimed to offer new functionalities, but in reality, they executed harmful code on developers' machines. The use of legitimate dependencies as a vector for malware delivery demonstrates an evolution in threat actor tactics, making detection more difficult. Researchers also noted a broader trend of increasing malware submissions to the VS Code Marketplace, including incidents where legitimate extensions were compromised through malicious pull requests that added harmful dependencies. This incident underscores the need for heightened scrutiny of third-party code and dependencies in development environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following the report, all identified malicious extensions were removed from the VS Code Marketplace. Users who had installed them were advised to scan their systems for signs of compromise.
After identifying the campaign, ReversingLabs reported all 19 malicious extensions to Microsoft. The researchers also published indicators of compromise to help defenders investigate potential infections.
In December 2025, ReversingLabs researchers identified the long-running campaign affecting the VS Code Marketplace and analyzed how the extensions hid malware in dependency folders. The researchers also noted a broader rise in malicious VS Code extensions during 2025 compared with 2024.
The malicious extensions bundled modified dependency folders, including trojanized versions of the npm packages 'path-is-absolute' and in some cases '@actions/io'. When VS Code started, the altered code executed a JavaScript dropper that deployed malware, including binaries disguised as a PNG file, a Rust-based trojan, and use of LOLBINs such as cmstp.exe.
A campaign involving 19 malicious Visual Studio Code Marketplace extensions became active in February 2025, targeting developers through trojanized extensions. The extensions were published as version 1.0.0 and included names such as Malkolm Theme, PandaExpress Theme, Prada 555 Theme, and Priskinski Theme.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcebleepingcomputer.com
Open sourcereversinglabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.