VSCode Extension - Tool

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 4, 2025
Last Seen
December 4, 2025

VSCode Extension is a tool tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 4, 2025; most recent activity December 4, 2025.

Overview

The VSCode Extension refers to a malicious Visual Studio Code extension used as an attack tool to deliver payloads. Threat actors weaponize a VSCode extension to deploy Anivia Loader and OctoRAT, leveraging legitimate developer tooling to compromise endpoints. This highlights how widely adopted development environments can be abused for initial access and remote-control capabilities.

Related Threat Clusters

  • Malicious VSCode Extension Distributes Anivia Loader and OctoRAT

    A malicious Visual Studio Code (VSCode) extension has been identified as a vector for deploying the Anivia Loader and OctoRAT malware. This threat primarily affects users of the VSCode platform, enabling attackers to…

    2 articles · Updated December 4, 2025

Recent Intelligence Reports

  • Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT — Cybersecuritynews · December 4, 2025

Related Entities

CVSS v3.1 Breakdown