An array of 77 extensions on the Open VSX marketplace has been identified as imitating genuine developer tools, thereby sharing details about the computers and development setups where they were installed. The remaining payloads transmit developer-related information such as local hostnames, operating system usernames, editor names, versions, machine IDs, platform details, locale settings, timezone data, open workspace paths, and other relevant metadata. The extensions that are part of the second set have also been found to perform additional steps: Inspect files within the .git directory to gather information about remote repositories, organizations, developer email domains, current branches, and HEAD commit SHA hashes.
The news reveals that 450 distinct npm packages, totaling 2,244 artifacts, have fallen victim to a new software supply chain attack aimed at delivering an information stealer and leveraging stolen npm tokens to distribute trojanized versions containing the same malware. Additionally, the malware can use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating another developer-to-developer infection path. This sample also demonstrates techniques not documented in earlier Shai-Hulud reports: it downloads a standalone Bun runtime to execute a bundled second stage, employs a modular dispatcher with separate GitHub and domain-based delivery channels, and sets autostart hooks in .claude and .vscode files to target developers and AI coding agents.












