A supply chain attack was discovered involving 19 malicious Visual Studio Code extensions that leveraged typosquatting and steganography techniques to distribute a Rust-based trojan. These extensions, masquerading as legitimate tools, were designed to compromise developer environments by deploying malware built with the Rust programming language, highlighting the growing threat of malicious code infiltrating popular development platforms through third-party add-ons.
The use of Rust for malware development is part of a broader trend, as threat actors increasingly adopt modern languages like Rust to create cross-platform threats that are harder to analyze and detect. The specific trojan deployed via the VS Code extensions is related to the emerging "Luca Stealer," a Rust-based information stealer capable of targeting both Linux and Windows systems. This shift to Rust-based malware presents new challenges for defenders, requiring updated analysis techniques and tools to effectively identify and mitigate these sophisticated threats.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
A supply-chain campaign targeting Visual Studio Code was discovered involving 19 malicious extensions. The attackers used typosquatting and steganography to deliver a Rust-based trojan through the extension ecosystem.
Researchers analyzed Luca Stealer, an open-source information stealer written in Rust that targets Linux and Windows systems. The analysis highlighted reverse-engineering challenges and indicators such as Rust build artifacts, specific strings, and a related sample hash.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.