VSCode Extension is a tool tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 4, 2025; most recent activity December 4, 2025.
The VSCode Extension refers to a malicious Visual Studio Code extension used as an attack tool to deliver payloads. Threat actors weaponize a VSCode extension to deploy Anivia Loader and OctoRAT, leveraging legitimate developer tooling to compromise endpoints. This highlights how widely adopted development environments can be abused for initial access and remote-control capabilities.
A malicious Visual Studio Code (VSCode) extension has been identified as a vector for deploying the Anivia Loader and OctoRAT malware. This threat primarily affects users of the VSCode platform, enabling attackers to…