Malicious VSCode Extension Launches Multi-Stage Attack Chain with Anivia Loader and OctoRAT

Dec. 4, 2025, 11:09 a.m.

Description

A malicious Visual Studio Code extension named 'prettier-vscode-plus' was discovered on the official VSCode Marketplace, impersonating the legitimate Prettier formatter. This extension served as the entry point for a multi-stage malware chain, starting with the Anivia loader, which decrypted and executed further payloads in memory. The final stage, OctoRAT, is a comprehensive remote access toolkit providing over 70 commands for surveillance, file theft, remote desktop control, persistence, privilege escalation, and harassment. The attack chain employs sophisticated techniques like AES encryption, process hollowing, and UAC bypass. The threat actor's GitHub repository showed active payload rotation to evade detection. This supply-chain attack highlights the evolving threats targeting developers and the abuse of trusted tools in their ecosystem.

Date

  • Created: Dec. 4, 2025, 10:32 a.m.
  • Published: Dec. 4, 2025, 10:32 a.m.
  • Modified: Dec. 4, 2025, 11:09 a.m.

Indicators

  • f4e5b1407f8a66f7563d3fb9cf53bae2dc3b1f1b93058236e68ab2bd8b42be9d
  • b8bc4a9c9cd869b0186a1477cfcab4576dfafb58995308c1e979ad3cc00c60f2
  • 9a870ca9b0a47c5b496a6e00eaaa68aec132dd0b778e7a1830dadf1e44660feb
  • 360e6f2288b6c8364159e80330b9af83f2d561929d206bc1e1e5f1585432b28f
  • 279f7ab5979e82caa75ac4d7923ee1f3d76fe8c3edc6cc124d619a8f7441eb5e
  • 178.16.55.109
  • 158.94.210.76
  • 158.94.210.52