ThreatCluster

Malicious ClawdBot Agent VS Code Extension Discovered Deploying ScreenConnect RAT

First seen 29 Jan 2026, 22:53 UTC GbhackersCybersecuritynews 54

Article Content

Browse articles
ThreatCluster

A malicious VS Code extension named 'ClawdBot Agent' was discovered on January 27, 2026. This fake extension, posing as an AI-powered assistant, targets developers and deploys the ScreenConnect Remote Access Trojan (RAT). Users of legitimate coding tools are at risk of compromising their systems through this deceptive software.