Curl exfiltration to i.apee.my.id from hidden VS Code terminal
Detects the use of curl.exe or curl to communicate with the malicious domain 'i.apee.my.id', initiated by a VS Code integrated terminal process. This behavior is indicative of malicious VS Code extensions exfiltrating data via a hidden terminal session.
Microsoft Sentinel (KQL)

