Fake AI Assistant, Real RAT: Malicious “ClawdBot Agent” Extension Weaponizes VS Code Marketplace

Listen to this Post

Featured Image

Introduction: When Developer Tools Become the Attack Surface

The Visual Studio Code ecosystem has become a critical dependency for modern software development, trusted by millions of engineers worldwide. That trust is precisely what attackers exploited with “ClawdBot Agent,” a malicious extension that masqueraded as a next-generation AI coding assistant. By impersonating a viral AI tool and quietly deploying a full-featured remote access trojan, the campaign demonstrated how developer platforms are increasingly being abused as high-value supply-chain entry points. Even experienced developers were caught off guard, installing what looked like a legitimate productivity tool—only to hand over control of their systems.

Summary of the Original Incident

Security researchers identified a malicious Visual Studio Code extension named “ClawdBot Agent” published on the official Visual Studio Marketplace. The extension claimed to be an AI-powered coding assistant leveraging popular large language models such as Claude, GPT-4, and Gemini. In reality, it acted as a delivery mechanism for a weaponized ScreenConnect Remote Access Trojan (RAT) on Windows systems. Microsoft removed the extension shortly after disclosure, but not before developers had already installed a fully operational backdoor.

The extension closely mimicked the branding and naming of the legitimate and viral clawd.bot AI tool, which had gained popularity across social platforms. Attackers registered the name early, built a polished extension page, used professional icons, and integrated real AI APIs from OpenAI, Anthropic, Google, Ollama, Groq, Mistral, and OpenRouter. This ensured the extension actually worked as advertised, offering functional code completion and AI assistance, which significantly reduced suspicion and delayed detection.

Technically, the extension abused VS Code’s lifecycle by triggering automatically at startup using “activationEvents”: [“onStartupFinished”]. Once activated, its activate() function immediately invoked a hidden initCore() routine before executing any legitimate AI-related logic. This function fetched a remote configuration file from clawdbot.getintwopc[.]site, which listed multiple payload components designed to resemble a trojanized Electron application.

Among these files was Code.exe, a legitimate ScreenConnect binary flagged by antivirus vendors as a remote administration tool rather than outright malware. When executed, it installed itself into C:\Program Files (x86)\ScreenConnect Client (083e4d30c7ea44f7)\, deployed ScreenConnect.ClientService.exe, and initiated outbound communication to meeting.bulletmailer[.]net:8041 using attacker-controlled RSA keys.

To ensure reliability, the attackers implemented redundant loaders and fallback mechanisms. A Rust-based sideloading DLL named DWrite.dll hijacked the ScreenConnect loading process and fetched additional payloads from Dropbox, disguised as a Zoom update MSI. Temporary staging occurred under %TEMP%\Lightshot, and execution was hidden using detached process spawning and Windows API obfuscation. Additional fallbacks included hardcoded JavaScript URLs and a PowerShell-driven batch script retrieved from darkgptprivate[.]com.

The infrastructure was deliberately layered. Primary domains hid behind Cloudflare, while secondary assets resolved to hosting providers in Seychelles. The campaign abused trusted tools, clean signatures, and developer familiarity to evade traditional defenses. Security teams advised immediate removal of the extension, uninstalling ScreenConnect, blocking command-and-control endpoints, rotating API keys, and performing full system scans. The incident underscored the growing risk of malicious extensions in trusted development marketplaces.

What Undercode Say:

Developer Trust Is the New Perimeter

This campaign reinforces a harsh reality: developer environments are no longer just productivity zones—they are privileged execution contexts. An extension running inside VS Code inherits the trust of the developer, access to the filesystem, network connectivity, and often credentials or API tokens. Attackers understand that compromising a developer workstation can be far more valuable than targeting an end user.

Functional Malware Is Harder to Spot

One of the most effective aspects of ClawdBot Agent was that it actually worked. By delivering real AI features backed by legitimate APIs, the attackers eliminated the primary red flag users rely on—broken or suspicious behavior. This is a shift from crude malware to dual-use malicious tooling, where usefulness becomes camouflage.

Abuse of Legitimate RMM Tools Is Strategic

ScreenConnect is not malware by default. It is a widely used remote management tool trusted by enterprises. By embedding it as the primary payload, attackers bypassed many antivirus engines and behavioral detections. This “Bring Your Own RMM” tactic mirrors trends seen in ransomware intrusions and advanced persistent threat operations.

Naming Collisions Are an Underrated Risk

The attackers did not invent a random brand. They deliberately cloned the name, style, and reputation of an already popular AI assistant. Marketplace users rarely scrutinize publisher identities deeply, especially when branding appears familiar. This highlights a systemic weakness in extension marketplaces where name squatting and visual mimicry remain insufficiently controlled.

Multi-Layered Fallbacks Signal Professional Operations

The presence of multiple loaders, alternate payload sources, and backup infrastructure indicates planning and operational maturity. This was not a proof-of-concept attack. It was engineered for resilience, persistence, and scale, ensuring that even partial takedowns would not immediately neutralize infections.

Developer Machines Are High-Value Targets

A compromised developer workstation can expose source code, credentials, signing keys, cloud access tokens, and CI/CD secrets. In that context, this campaign should be viewed not merely as malware distribution, but as a potential stepping stone to broader supply-chain compromises affecting downstream software users.

VS Code Marketplace Moderation Is Reactive

Microsoft acted quickly once notified, but the extension was live long enough to infect systems. Current moderation largely relies on post-publication reporting rather than proactive behavioral analysis. As extensions gain more power and complexity, reactive takedowns will no longer be sufficient.

AI Branding Is Becoming a Social Engineering Weapon

AI is currently one of the strongest trust signals in tech marketing. Attackers exploited that hype masterfully. Any tool claiming access to multiple top-tier models instantly feels credible. This incident shows how AI branding itself has become a social engineering vector.

Antivirus Alone Is No Longer Enough

Traditional endpoint security struggled because the payload components were cleanly signed and widely used in legitimate contexts. Detection relied more on network indicators, behavioral anomalies, and threat intelligence than on static malware signatures.

Extension Hygiene Must Become Standard Practice

Developers rarely audit installed extensions once productivity workflows are established. This case demonstrates the need for regular reviews, publisher verification, permission awareness, and minimal-extension policies, especially in professional environments.

The Bigger Supply-Chain Picture

This attack fits into a broader trend where adversaries target upstream tools—IDEs, package managers, CI plugins—rather than finished applications. Compromising the builder is often more efficient than attacking every end user individually.

Fact Checker Results

✅ The extension was published on the official Visual Studio Marketplace and later removed by Microsoft.

✅ ScreenConnect binaries used in the attack are legitimate remote administration tools abused for malicious access.

❌ No evidence suggests this was an accidental misconfiguration; indicators point to deliberate malicious intent.

Prediction

🔮 Similar AI-themed malicious extensions will continue to appear as attackers exploit hype and trust in developer tools.
🔮 Marketplaces will face pressure to implement stricter publisher verification and automated behavioral scanning.
🔮 Developers and organizations will increasingly treat IDE extensions as part of their formal security attack surface.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon