Incident · malware · fake extension
Fake VS Code extension claiming to be Moltbot
Security researchers reported a malicious VS Code extension that claimed to be a Moltbot/Clawdbot coding assistant, but delivered a remote-access payload.
What reports say (high level)
- Extension was listed in the VS Code Marketplace and later removed (per reports).
- It downloaded additional payload/config and attempted to establish remote access.
- Attackers capitalized on Moltbot popularity; reports note there was no legitimate extension.
What to do now
1
Remove the extension
Uninstall and check for persistence.
2
Rotate tokens
Assume credentials may have been harvested.
3
Rebuild from clean state
A clean reinstall/snapshot rollback can be faster than manual cleanup.