BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious Moltbot VS Code Extension Installs ScreenConnect!!

Malicious VS Code extension posing as Moltbot deployed a preconfigured ScreenConnect backdoor (with DLL/batch fallbacks) while exposed Moltbot instances leaked credentials and conversations

  • A malicious Visual Studio Code extension impersonating Moltbot delivered a persistent remote-access payload to infected machines.
  • The extension auto-ran on IDE start, fetched a remote config.json, and installed a preconfigured ConnectWise ScreenConnect client that phoned home to an attacker-controlled host.
  • Multiple fallback delivery methods existed, including a sideloaded DLL and a batch script, ensuring payload delivery if primary infrastructure failed.
  • Separately, many publicly reachable Moltbot instances exposed credentials and conversation data, enabling impersonation and data theft without further exploit.

A newly published Visual Studio Code extension called "ClawdBot Agent – AI Coding Assistant" (identifier "clawdbot.clawdbot-agent") appeared on January 27, 2026 and was later removed by Microsoft. Security researchers first Malware“>flagged the extension after it advertised itself as a free AI coding assistant for Visual Studio Code while secretly deploying a remote-access payload.

- Advertisement -

The extension executed automatically when the IDE launched, downloaded a file named "config.json" from the domain clawdbot.getintwopc[.]site, and ran an executable named "Code.exe" that installed a legitimate remote-desktop tool, ConnectWise ScreenConnect. The client then connected to meeting.bulletmailer[.]net:8041 to give attackers persistent access.

According to Aikido, "The attackers set up their own ScreenConnect relay server, generated a pre-configured client installer, and distributed it through the VS Code extension," allowing the client to immediately phone home. The extension also included a fallback that downloaded a Rust-written DLL named "DWrite.dll" for sideloading and retrieving the same payload from Dropbox.

Additional hard-coded URLs in the extension and a batch-script fallback that fetched payloads from darkgptprivate[.]com increased delivery resilience. The incident exploited the popularity of Moltbot, which has grown rapidly on GitHub, exceeding 85,000 stars as of this report and offering users local LLM assistants accessible via platforms listed on the project site.

Researchers warned about widespread insecure deployments of Moltbot. Jamieson O’Reilly of Dvuln noted that hundreds of unauthenticated instances exposed configuration data and credentials, and that "The real problem is that Clawdbot agents have agency," as shown in his post. Security firm Intruder reported misconfigurations, prompt-injection risks, and compromised instances in a published analysis.

- Advertisement -

Users running default Moltbot configurations are advised to audit settings, revoke integrations, and implement network controls, following the project’s published security guidance. Additional discussion of agent risks and distribution concerns appears in related posts, including a note about backdoored skills on MoltHub and prompt-injection risks described by IEEE Spectrum.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

China Orders Meta to Unwind $2B AI Startup Deal

Chinese regulators have ordered Meta to fully unwind its $2 billion acquisition of AI...

Quantum Crypto Prize Called “Classical Parlor Trick”

Project Eleven, a quantum cybersecurity startup backed by major crypto investors, awarded one Bitcoin...

Kbank, Ripple Partner on Blockchain Remittances

South Korea's Kbank and Ripple have signed a strategic partnership to test blockchain-based overseas...

BofA Reiterates $300 Nvidia Target; Stock Soars 18%

NVIDIA's (NVDA) stock gained over 18% in a month, closing at $208.26 on April...

Western Union to Launch Solana-Based Stablecoin Next Month

Western Union will launch its Solana-based stablecoin, USDPT, next month, targeting agent network settlements.The...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading