Malicious fast-draft Open VSX Extension Distributes RAT and Infostealer

Malicious fast-draft Open VSX Extension Distributes RAT and Infostealer

First seen 19 Mar 2026, 10:11 UTC Aikido.DevGbhackersCybersecuritynews 85% similarity 71.0

Article Content

Browse articles
ThreatCluster

The KhangNghiem/fast-draft extension on Open VSX was found to contain multiple malicious releases that deploy a remote access trojan (RAT) and an infostealer. Versions 0.10.89, 0.10.105, 0.10.106, and 0.10.112 were confirmed to be compromised, while versions 0.10.88 and 0.10.111 were clean. The malicious versions utilize a GitHub-hosted downloader to fetch and execute payloads, indicating a potential compromise of the publisher or a stolen token rather than intentional malicious behavior by the maintainer. The extension has over 26,000 downloads, raising concerns about the scope of potential impact on developers. The latest clean version, 0.10.135, was released on 2026-03-17 and does not exhibit the same malicious behavior. The issue was reported to the maintainer on 2026-03-12, but the GitHub issue remains open as of the latest article date.

Key Points: • The fast-draft extension was compromised in specific versions, allowing malware deployment. • Malicious releases used a GitHub downloader to execute a RAT and infostealer on user machines. • The latest clean version of the extension was released on 2026-03-17, but previous versions are still a risk.

ThreatCluster AI

Timeline

2026-03-12
Issue reported to maintainer via GitHub
2026-03-17
Latest clean version 0.10.135 released
2026-03-18
Article published detailing the compromise
2026-03-19
Second article published confirming malicious activity

Community

Browse all →

Tracked Entities in This Story