Cybersecuritynews
Malicious fast-draft Open VSX Extension Distributes RAT and Infostealer
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The KhangNghiem/fast-draft extension on Open VSX was found to contain multiple malicious releases that deploy a remote access trojan (RAT) and an infostealer. Versions 0.10.89, 0.10.105, 0.10.106, and 0.10.112 were confirmed to be compromised, while versions 0.10.88 and 0.10.111 were clean. The malicious versions utilize a GitHub-hosted downloader to fetch and execute payloads, indicating a potential compromise of the publisher or a stolen token rather than intentional malicious behavior by the maintainer. The extension has over 26,000 downloads, raising concerns about the scope of potential impact on developers. The latest clean version, 0.10.135, was released on 2026-03-17 and does not exhibit the same malicious behavior. The issue was reported to the maintainer on 2026-03-12, but the GitHub issue remains open as of the latest article date.
Key Points: • The fast-draft extension was compromised in specific versions, allowing malware deployment. • Malicious releases used a GitHub downloader to execute a RAT and infostealer on user machines. • The latest clean version of the extension was released on 2026-03-17, but previous versions are still a risk.