Malicious VS Code Extensions Disguised as Dev Tools Hide Backdoors and Shellcode
cyb3rops · x · 2026-08-13
Security firm Knostic has uncovered a malicious VS Code extension campaign dubbed SaassyCode. Attackers distributed extensions disguised as Trello and Roblox development tools (e.g., TrelloWorks.trello-board and ManageRBLX) via the VS Code marketplace.
These extensions silently download and execute a BAT loader upon startup, establish persistence via scheduled tasks, and inject embedded shellcode into trusted Windows processes. The extensions have since been removed.
More from coding & agent
- Hamel Husain Summarizes 13 AI Engineering Sessions: Key Takeaways on Retrieval, Post-training, and Evals — HamelHusain · 2026-08-13
- Why hand-coding beats AI agents: the cognitive benefit of slowness — GrantCuster · 2026-08-13
- Scion OSS Agent Orchestrator: Let Agents Figure Out Usage via CLI Help — steren · 2026-08-13
- Rebuilding the 90s Internet with AI Agents: A Feasibility Discussion — Jaded-Percentage-130 · 2026-08-13
- What Actually Breaks When AI Agents Go to Production? Reddit Discusses — Diegokernel · 2026-08-13
- PageSpace Cloud Agents: AI Agents Discover Context on Demand, No Giant Prompts Needed — ericelliott_ · 2026-08-13