Malicious Pull Request Affects Over 6,000 Developers Through Vulnerable Ethcode VS Code Extension

Published:

spot_img

Rising Risks in Cybersecurity: Supply Chain Attack on Ethcode Extension

Cybersecurity experts have recently raised alarms about a significant supply chain attack targeting a Microsoft Visual Studio Code (VS Code) extension known as Ethcode. This extension, which has been installed over 6,000 times, is integral for developers working with Solidity smart contracts on Ethereum blockchain networks.

The Discovery of the Attack

According to security research firm ReversingLabs, the vulnerability arose from a GitHub pull request made on June 17, 2025, by a user pseudonymously named Airez299. Initially developed by 7finney in 2022, Ethcode primarily assists developers in deploying and executing smart contracts in environments powered by the Ethereum Virtual Machine (EVM).

Prior to the intrusion, the last legitimate update to Ethcode occurred on September 6, 2024. The malicious pull request introduced by Airez299 included ostensibly beneficial updates, claiming to modernize the codebase with a new testing framework and various dependency updates.

The Hidden Threat

While the update might have appeared advantageous—after a nine-month dormancy—it concealed a serious threat. The attack reportedly incorporated two lines of malicious code hidden within 43 commits, totaling around 4,000 lines of changes that compromised the security of the extension. Specifically, the inclusion of an npm package named keythereum-utils was a key element of the exploit, as it connected directly to the VS Code extension’s TypeScript file.

The keythereum-utils library, now removed from the npm registry, was heavily obfuscated and designed to download a second-stage payload once installed. Despite being downloaded nearly 500 times before its removal, its true purpose was to execute unauthorized actions on users’ systems.

The Threat’s Capabilities

Security researcher Petar Kirhmajer detailed that the deobfuscated code from keythereum-utils activates a hidden PowerShell command, which downloads and executes a batch file from a publicly accessible file-hosting service. Although the exact nature of this payload remains undetermined, it is suspected to be malware capable of either stealing cryptocurrency or corrupting the smart contracts developed by Ethcode users.

Following responsible disclosure to Microsoft, the extension was promptly removed from the VS Code Extensions Marketplace. After eliminating the malicious dependency, Ethcode was restored for public use.

Broader Context of Supply Chain Attacks

The incident with Ethcode highlights an alarming trend in the realm of cybersecurity: increasing attacks on software supply chains. As cyber threats evolve, attackers are more frequently exploiting well-established open-source repositories like PyPI and npm to introduce malware into developer environments.

ReversingLabs noted that the GitHub account Airez299, which initiated the pull request, was newly created on the same day as the request—suggesting it was a disposable account intended solely for executing the attack.

Statistics on Open-Source Malware

The significance of the Ethcode incident is underscored by alarming statistics from Sonatype. In the second quarter of 2025 alone, over 16,279 instances of open-source malware were identified, marking a staggering 188% increase year-over-year. Among these, more than 4,400 packages were specifically designed to harvest sensitive information, such as user credentials and API tokens.

Furthermore, incidences of malware aimed at data corruption saw a marked increase, constituting 3% of all malicious packages. This increase mirrors a troubling trend: malware is becoming increasingly sophisticated, targeting developers and organizations through their trusted development pipelines.

Ongoing Threats from Advanced Attack Groups

Sophisticated threat actors, such as North Korea-linked groups like the Lazarus Group, have reportedly circulated over 107 malicious packages, which were collectively downloaded more than 30,000 times. Other groups have also been linked to more than 90 npm packages focused on system information harvesting, further emphasizing the scale and persistence of these campaigns aimed at users’ data.

New Developments in Browser-Based Attacks

In addition to the supply chain attack on Ethcode, new threats have emerged among browser extensions. Research by Socket has identified eight fake gaming-related extensions in the Mozilla Firefox Add-ons store that possess varying degrees of malicious functionality. These include adware, Google OAuth token theft, and deceptive redirects to gambling sites.

As cybersecurity threats continue to evolve, developers and users alike must remain vigilant. With browser extensions being a favored target due to their broad permissions and trusted nature, the infiltration of malicious components shows no sign of slowing. Each new attack campaign underscores the importance of rigorous security practices and the examination of dependencies within our software development processes.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...