VS Code Extension Process Beaconing to Cloudflare Workers for Secondary Payload (Solidity Pro Pattern)
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
Microsoft Sentinel (KQL)

