The SadiqShuaibu campaign: 6 fake npm dependency checkers that embed a GitHub token and run remote code The roqueue-tools DevFlow campaign: 2 fake project-flow extensions that fetch JavaScript from a DuckDNS host and run it Copilot for KeyBank — a 3 KB VSIX that beacons through github-cdn.net and waits for eval The boardflow campaign: 15 fake Kanban VS Code extensions that download and run a remote payload The heyheyhey campaign: 6 fake Roblox VS Code extensions that fetch and run a remote script from GitHub 28 Evil-Twin Open VSX Extensions - A New Wave of Coordinated Beacons Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer Supply Chain Security in 2026: The SBOM Layer Is Broken The oast.fun campaign: VS Code extensions that exfiltrate system identifiers over DNS on every IDE launch Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm Dropper The Windows Installer Dropper Family: VS Code Extensions Living off the Land The Fake MSDN DLL Dropper and the Counterfeit C++ Runtime DigitalBarberTrim's Side-Car Loader: A VSIX Installer That Pivots Across VS Code Forks OmniRouter AI: A Dropper in a Chat Sidebar The Solidity Extension That Stole from the Clipboard: Inside the ethdevtools Crypto Swap The Scanner Is the Target: How IDE Extension Malware Uses Prompt Injection to Evade AI Review The Builder Kit Behind ShopifySTORES and State Diagram: A VSIX Dropper Campaign GLASSWORM.WASM: Deconstructing the TinyGo WebAssembly Loader Hitting Open VSX Hiding Commands in Icons: The nbtga Hello-World Malware Lab Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace A Deeper Look at GLASSWORM's Solana Variant Recognized in the Open VSX Security Hall of Fame The CISO's Guide to IDE Security in 2026 The Malware Factory: GLASSWORM Forensics in Open VSX Weaponizing Empty Github Repositories with Releases The Ghost in the Marketplace Weaponizing Extension Packs with PackRAT Yeeth - 2025 Year in Review Secret Scanning with Aho-Corasick A Deeper Look at RustImplant SleepyDuck Evolution WhiteCobra Beginnings The SadiqShuaibu campaign: 6 fake npm dependency checkers that embed a GitHub token and run remote code The roqueue-tools DevFlow campaign: 2 fake project-flow extensions that fetch JavaScript from a DuckDNS host and run it Copilot for KeyBank — a 3 KB VSIX that beacons through github-cdn.net and waits for eval The boardflow campaign: 15 fake Kanban VS Code extensions that download and run a remote payload The heyheyhey campaign: 6 fake Roblox VS Code extensions that fetch and run a remote script from GitHub 28 Evil-Twin Open VSX Extensions - A New Wave of Coordinated Beacons Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer Supply Chain Security in 2026: The SBOM Layer Is Broken The oast.fun campaign: VS Code extensions that exfiltrate system identifiers over DNS on every IDE launch Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm Dropper The Windows Installer Dropper Family: VS Code Extensions Living off the Land The Fake MSDN DLL Dropper and the Counterfeit C++ Runtime DigitalBarberTrim's Side-Car Loader: A VSIX Installer That Pivots Across VS Code Forks OmniRouter AI: A Dropper in a Chat Sidebar The Solidity Extension That Stole from the Clipboard: Inside the ethdevtools Crypto Swap The Scanner Is the Target: How IDE Extension Malware Uses Prompt Injection to Evade AI Review The Builder Kit Behind ShopifySTORES and State Diagram: A VSIX Dropper Campaign GLASSWORM.WASM: Deconstructing the TinyGo WebAssembly Loader Hitting Open VSX Hiding Commands in Icons: The nbtga Hello-World Malware Lab Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace A Deeper Look at GLASSWORM's Solana Variant Recognized in the Open VSX Security Hall of Fame The CISO's Guide to IDE Security in 2026 The Malware Factory: GLASSWORM Forensics in Open VSX Weaponizing Empty Github Repositories with Releases The Ghost in the Marketplace Weaponizing Extension Packs with PackRAT Yeeth - 2025 Year in Review Secret Scanning with Aho-Corasick A Deeper Look at RustImplant SleepyDuck Evolution WhiteCobra Beginnings
Latest Briefing

All Briefings

The roqueue-tools DevFlow campaign: 2 fake project-flow extensions that fetch JavaScript from a DuckDNS host and run it Threat Intel
Aug 20, 2026

The roqueue-tools DevFlow campaign: 2 fake project-flow extensions that fetch JavaScript from a DuckDNS host and run it

Two project-flow extensions sit quietly for five minutes after you open your editor. Then they reach out to a free DuckDNS subdomain over...

Read Briefing
Copilot for KeyBank — a 3 KB VSIX that beacons through github-cdn.net and waits for eval Threat Intel
Aug 19, 2026

Copilot for KeyBank — a 3 KB VSIX that beacons through github-cdn.net and waits for eval

A single-file VS Code extension on the Microsoft Marketplace impersonates Copilot, DeepSeek, PyPI and KeyBank. On activation it phones gi...

Read Briefing
The boardflow campaign: 15 fake Kanban VS Code extensions that download and run a remote payload Threat Intel
Aug 19, 2026

The boardflow campaign: 15 fake Kanban VS Code extensions that download and run a remote payload

Everyone wants a Kanban board inside their editor. Fifteen fake ones hit the Marketplace over ten weeks, each one a different publisher a...

Read Briefing
The heyheyhey campaign: 6 fake Roblox VS Code extensions that fetch and run a remote script from GitHub Threat Intel
Aug 18, 2026

The heyheyhey campaign: 6 fake Roblox VS Code extensions that fetch and run a remote script from GitHub

A Kanban board for Roblox developers sounds harmless enough. Six of them hit the VS Code Marketplace in three days — same version, same s...

Read Briefing
28 Evil-Twin Open VSX Extensions - A New Wave of Coordinated Beacons Threat Intel
Aug 13, 2026

28 Evil-Twin Open VSX Extensions - A New Wave of Coordinated Beacons

Yeeth Security found 28 counterfeit extensions on Open VSX that exfiltrate the editor, hostname and extension identity to a remote server...

Read Briefing
Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer Threat Intel
Aug 6, 2026

Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer

Yeeth Security tracked a multi-version VS Code: extension campaign that posed as a Solidity tool. Early versions dropped an encrypted Pyt...

Read Briefing
Supply Chain Security in 2026: The SBOM Layer Is Broken Security Research
Jul 27, 2026

Supply Chain Security in 2026: The SBOM Layer Is Broken

Most organizations can now generate a software bill of materials (SBOM), but few can turn it into a clean, remediated release. The supply...

Read Briefing
The oast.fun campaign: VS Code extensions that exfiltrate system identifiers over DNS on every IDE launch Threat Intel
Jul 23, 2026

The oast.fun campaign: VS Code extensions that exfiltrate system identifiers over DNS on every IDE launch

A language extension called lotse-language-vscode shows up at version 13.37 — leet for elite. It declares one command: Hello World. And o...

Read Briefing
Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm Dropper Malware Analysis
Jul 2, 2026

Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm Dropper

The VS Code extension ascii-fetcher.ascii-fetcher looked harmless because almost all of its code lived in a dependency. That dependency, ...

Read Briefing
The Windows Installer Dropper Family: VS Code Extensions Living off the Land Threat Intel
Jul 2, 2026

The Windows Installer Dropper Family: VS Code Extensions Living off the Land

In late June Argus caught a cluster of VS Code: droppers that all abused Windows installer primitives — curl|bash, irm|iex, cscript, msht...

Read Briefing
The Fake MSDN DLL Dropper and the Counterfeit C++ Runtime Malware Analysis
Jul 2, 2026

The Fake MSDN DLL Dropper and the Counterfeit C++ Runtime

The worldline.aicodefix campaign downloads a counterfeit VCRUNTIME140.dll from a fake Microsoft domain, plants it inside a spoofed Edge u...

Read Briefing
DigitalBarberTrim's Side-Car Loader: A VSIX Installer That Pivots Across VS Code Forks Malware Analysis
Jul 2, 2026

DigitalBarberTrim's Side-Car Loader: A VSIX Installer That Pivots Across VS Code Forks

The DigitalBarberTrim.html-entity-codec campaign version-cycled through clean, malicious, and stub releases. The payload was a hidden i.j...

Read Briefing
OmniRouter AI: A Dropper in a Chat Sidebar Threat Intel
Jun 22, 2026

OmniRouter AI: A Dropper in a Chat Sidebar

A VS Code: extension promising one sidebar for Claude, GPT, Gemini and DeepSeek instead runs a zero-width-obfuscated command that downloa...

Read Briefing
The Solidity Extension That Stole from the Clipboard: Inside the ethdevtools Crypto Swap Threat Intel
Jun 21, 2026

The Solidity Extension That Stole from the Clipboard: Inside the ethdevtools Crypto Swap

A fake Solidity language extension hid in VS Code: for weeks before activating. Once it did, it scraped the clipboard for crypto seeds an...

Read Briefing
The Scanner Is the Target: How IDE Extension Malware Uses Prompt Injection to Evade AI Review Threat Research
Jun 18, 2026

The Scanner Is the Target: How IDE Extension Malware Uses Prompt Injection to Evade AI Review

Malicious VS Code and Open VSX extensions are now embedding fake system instructions and context floods aimed directly at the AI-powered ...

Read Briefing
The Builder Kit Behind ShopifySTORES and State Diagram: A VSIX Dropper Campaign Malware Analysis
Jun 18, 2026

The Builder Kit Behind ShopifySTORES and State Diagram: A VSIX Dropper Campaign

A retro-hunt across Argus scan history tied the ShopifySTORES Replit MSI dropper and the State Diagram STDX dropper to the same builder k...

Read Briefing
GLASSWORM.WASM: Deconstructing the TinyGo WebAssembly Loader Hitting Open VSX Malware Analysis
Jun 16, 2026

GLASSWORM.WASM: Deconstructing the TinyGo WebAssembly Loader Hitting Open VSX

Argus caught a variation of the GLASSWORM campaign and flagged seven malicious extension names. We uncover what the TinyGo-compiled WebAs...

Read Briefing
Hiding Commands in Icons: The nbtga Hello-World Malware Lab Malware Analysis
Jun 15, 2026

Hiding Commands in Icons: The nbtga Hello-World Malware Lab

Twenty-six versions of the same VS Code extension, each testing a different concealment technique. One of them hid its PowerShell downloa...

Read Briefing
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace Threat Intel
Jun 9, 2026

Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace

A notebook productivity tool turns into a full remote access implant whose architecture overlaps with two documented DPRK campaigns — Con...

Read Briefing
A Deeper Look at GLASSWORM's Solana Variant Malware Analysis
May 25, 2026

A Deeper Look at GLASSWORM's Solana Variant

A new wave on Open VSX, a two-tier Solana dead-drop, and a Go-based backdoor.

Read Briefing
Recognized in the Open VSX Security Hall of Fame Security Research
May 21, 2026

Recognized in the Open VSX Security Hall of Fame

Yeeth Security has been added to the Open VSX Security Hall of Fame as a security guardian. A look at the work that led here, and what it...

Read Briefing
The CISO's Guide to IDE Security in 2026 Security Research
May 21, 2026

The CISO's Guide to IDE Security in 2026

What developer-environment threats look like in 2026, and the controls security leaders should put in place. Written by Yeeth Security fr...

Read Briefing
The Malware Factory: GLASSWORM Forensics in Open VSX Threat Intel
Apr 28, 2026

The Malware Factory: GLASSWORM Forensics in Open VSX

Sixteen extensions in 48 hours. All share one author. A forensic walkthrough of how Bane, Yeeth Security's threat-intelligence knowledge ...

Read Briefing
Weaponizing Empty Github Repositories with Releases Threat Intel
Apr 6, 2026

Weaponizing Empty Github Repositories with Releases

A campaign of VS Code extensions using GitHub releases as a payload delivery mechanism — and blockchain RPCs as command-and-control

Read Briefing
The Ghost in the Marketplace Threat Intel
Mar 20, 2026

The Ghost in the Marketplace

Analyzing a Massive 174-Account Surge on Open VSX

Read Briefing
Weaponizing Extension Packs with PackRAT Threat Intel
Mar 13, 2026

Weaponizing Extension Packs with PackRAT

Dissecting a Downloader Abusing Extension Packs for Stealthy Distribution

Read Briefing
Yeeth - 2025 Year in Review Year in Review
Dec 31, 2025

Yeeth - 2025 Year in Review

A look back at what we did and where we are going.

Read Briefing
Secret Scanning with Aho-Corasick Security Research
Dec 28, 2025

Secret Scanning with Aho-Corasick

Why scalable secret detection is a systems problem that matters

Read Briefing
A Deeper Look at RustImplant Malware Analysis
Dec 5, 2025

A Deeper Look at RustImplant

Dissecting an Obfuscated Downloader with Anti-analysis Guardrails

Read Briefing
SleepyDuck Evolution Malware Analysis
Nov 10, 2025

SleepyDuck Evolution

Technical analysis a new iteration of SleepyDuck, a tiny loader that behaves like a backdoor.

Read Briefing
WhiteCobra Beginnings Malware Analysis
Sep 3, 2025

WhiteCobra Beginnings

Technical analysis of one of the early WhiteCobra samples in the wild.

Read Briefing