VS Code Extension Dependency Dropper jsononifier Analysis
Score: 8/10

VS Code Extension Dependency Dropper jsononifier Analysis

An isolated malware dropper, ascii-fetcher, utilizes a malicious npm dependency named @jaymara/jsononifier to execute XOR-encoded commands on Windows systems via VS Code.

Executive Summary

On June 30, 2026, researchers identified a malicious VS Code extension named 'ascii-fetcher' (v1.0.0) on the Open VSX marketplace. The extension avoids detection by hosting its malicious logic within a secondary npm dependency, '@jaymara/jsononifier', rather than the extension's primary entry point. This allows the extension to appear benign to simple static analysis tools and manual reviews that do not inspect deep dependency trees.

The attack chain involves the dependency using environment checks to detect sandboxes and CI/CD environments before executing a XOR-decoded command via Node.js child_process. While the identified sample executed 'calc.exe', the underlying mechanism is designed for flexible payload delivery. The threat primarily impacts developers using VS Code and Open VSX, specifically targeting Windows platforms.

This discovery highlights the increasing sophistication of IDE-based supply chain attacks, where threat actors hide malicious behavior several layers deep in the dependency graph to bypass marketplace security scanners.

Key Details

Threat Name

jsononifier npm Dropper

Affects

—

Adversary

—

Malware/Tools

jsononifier, GLASSWORM, PackRAT, RustImplant, SleepyDuck, WhiteCobra

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth8

Sources