AI Series: Most Significant TTP – Malicious AI-IDE Extension / Coding-Assistant
Detects anomalous activity from IDEs or AI coding assistant extension host processes (e.g., VS Code, Cursor, JetBrains). The rule alerts when these processes spawn children that access sensitive local credential files, perform network connections to non-standard/unexpected domains, or modify critical CI/CD build script configuration files, which is indicative of a supply chain compromise within the developer environment.
YARA-L

