Executive Summary
On June 30, 2026, researchers identified a malicious VS Code extension named 'ascii-fetcher' (v1.0.0) on the Open VSX marketplace. The extension avoids detection by hosting its malicious logic within a secondary npm dependency, '@jaymara/jsononifier', rather than the extension's primary entry point. This allows the extension to appear benign to simple static analysis tools and manual reviews that do not inspect deep dependency trees.
The attack chain involves the dependency using environment checks to detect sandboxes and CI/CD environments before executing a XOR-decoded command via Node.js child_process. While the identified sample executed 'calc.exe', the underlying mechanism is designed for flexible payload delivery. The threat primarily impacts developers using VS Code and Open VSX, specifically targeting Windows platforms.
This discovery highlights the increasing sophistication of IDE-based supply chain attacks, where threat actors hide malicious behavior several layers deep in the dependency graph to bypass marketplace security scanners.
