Suspicious Execution from VS Code Extension

Detects suspicious process execution launched from a VS Code extension context (parent command line contains .vscode/extensions). Malicious extensions can run on startup and drop or execute payloads (e.g. RATs like ScreenConnect, script interpreters, or download utilities). This covers both script/LOLBin children and recently created executables from non-Program Files paths, as seen in campaigns such as the fake Clawdbot extension that installed ScreenConnect RAT.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/02/13"
  3integration = ["endpoint"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects suspicious process execution launched from a VS Code extension context (parent command line contains
 11.vscode/extensions). Malicious extensions can run on startup and drop or execute payloads (e.g. RATs like
 12ScreenConnect, script interpreters, or download utilities). This covers both script/LOLBin children and
 13recently created executables from non-Program Files paths, as seen in campaigns such as the fake Clawdbot
 14extension that installed ScreenConnect RAT.
 15"""
 16from = "now-9m"
 17index = ["logs-endpoint.events.process-*"]
 18language = "eql"
 19license = "Elastic License v2"
 20name = "Suspicious Execution from VS Code Extension"
 21note = """## Triage and analysis
 22
 23### Investigating Suspicious Execution from VS Code Extension
 24
 25Malicious VS Code extensions can use `activationEvents: ["onStartupFinished"]` to run as soon as the editor starts, then spawn scripts or download-and-execute payloads (e.g. weaponized ScreenConnect, batch/PowerShell downloaders). This rule flags process starts whose parent command line indicates execution from the extension host under `.vscode\\extensions\\` (or `/.vscode/extensions/`).
 26
 27### Possible investigation steps
 28
 29- Identify the extension: from the parent process command line, extract the path under `.vscode\\extensions\\` to get the extension id (e.g. `publisher.name-version`).
 30- Check whether that extension is approved; search the VS Code marketplace (or internal registry) for the same name and compare hashes.
 31- Inspect the child process: if it is cmd/powershell/curl/node/rundll32/etc., review command line and network/file activity; if it is a recently created executable (e.g. Code.exe, Lightshot), check path (e.g. %TEMP%\\Lightshot) and code signature.
 32- Correlate with network events (C2 domains, Dropbox/URL downloads) and with [Fake Clawdbot VS Code Extension](https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware) IOCs if relevant.
 33
 34### False positive analysis
 35
 36- Legitimate extensions that run scripts or tools (e.g. linters, formatters, task runners) can spawn cmd, node, or PowerShell. Tune by excluding known extension ids or by requiring additional conditions (e.g. outbound to unknown IPs).
 37- Extension development: running/debugging an extension from a workspace will spawn processes from `.vscode\\extensions\\`; consider excluding dev machines or specific parent paths.
 38
 39### Response and remediation
 40
 41- Uninstall the suspicious extension and restart VS Code.
 42- If payload was executed: check for ScreenConnect (or similar) installation paths and services, remove persisted artifacts, block IOCs at firewall/DNS, rotate any API keys or secrets that may have been entered into the extension.
 43"""
 44
 45setup = """## Setup
 46
 47This rule is designed for data generated by [Elastic Defend](https://www.elastic.co/security/endpoint-security), which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules.
 48
 49Setup instructions: https://ela.st/install-elastic-defend
 50"""
 51
 52references = [
 53    "https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware",
 54    "https://attack.mitre.org/techniques/T1204/",
 55    "https://attack.mitre.org/techniques/T1195/002/",
 56]
 57risk_score = 47
 58rule_id = "c3d4e5f6-a7b8-6c9d-0e1f-2a3b4c5d6e7f"
 59severity = "medium"
 60tags = [
 61    "Domain: Endpoint",
 62    "OS: Windows",
 63    "Use Case: Threat Detection",
 64    "Tactic: Initial Access",
 65    "Tactic: Execution",
 66    "Data Source: Elastic Defend",
 67    "Resources: Investigation Guide",
 68    "Noise: Medium",
 69    "Performance: Normal",
 70    "Profile: Recommended",
 71    "Threat: Supply Chain",
 72    "Threat: Living off the Land",
 73    "Rule Type: Event Correlation (EQL)",
 74    "Platform: Windows",
 75]
 76timestamp_override = "event.ingested"
 77type = "eql"
 78
 79query = '''
 80process where host.os.type == "windows" and event.action == "start" and
 81  process.parent.name : ("node.exe", "Code.exe") and
 82  process.parent.command_line != null and
 83  process.parent.command_line : ("*vscode*extensions*", "*extensionHost*") and
 84  (
 85    process.name : (
 86      "cmd.exe", "powershell.exe", "pwsh.exe", "rundll32.exe", "msiexec.exe",
 87      "curl.exe", "bitsadmin.exe", "wscript.exe", "cscript.exe", "mshta.exe",
 88      "node.exe"
 89    ) or
 90	
 91	// recently dropped PE
 92    process.Ext.relative_file_creation_time <= 500
 93  ) and 
 94  not (process.name : "cmd.exe" and process.args : ("npm.cmd config get prefix", "code -v", "chcp")) and 
 95  not (process.name : "python.exe" and process.parent.command_line : "*ms-python.vscode-*")
 96'''
 97
 98
 99
100[[rule.threat]]
101framework = "MITRE ATT&CK"
102
103[[rule.threat.technique]]
104id = "T1195"
105name = "Supply Chain Compromise"
106reference = "https://attack.mitre.org/techniques/T1195/"
107
108[[rule.threat.technique.subtechnique]]
109id = "T1195.002"
110name = "Compromise Software Supply Chain"
111reference = "https://attack.mitre.org/techniques/T1195/002/"
112
113[rule.threat.tactic]
114id = "TA0001"
115name = "Initial Access"
116reference = "https://attack.mitre.org/tactics/TA0001/"
117
118[[rule.threat]]
119framework = "MITRE ATT&CK"
120
121[[rule.threat.technique]]
122id = "T1059"
123name = "Command and Scripting Interpreter"
124reference = "https://attack.mitre.org/techniques/T1059/"
125
126[[rule.threat.technique.subtechnique]]
127id = "T1059.001"
128name = "PowerShell"
129reference = "https://attack.mitre.org/techniques/T1059/001/"
130
131[[rule.threat.technique.subtechnique]]
132id = "T1059.003"
133name = "Windows Command Shell"
134reference = "https://attack.mitre.org/techniques/T1059/003/"
135
136[[rule.threat.technique.subtechnique]]
137id = "T1059.007"
138name = "JavaScript"
139reference = "https://attack.mitre.org/techniques/T1059/007/"
140
141[[rule.threat.technique]]
142id = "T1204"
143name = "User Execution"
144reference = "https://attack.mitre.org/techniques/T1204/"
145
146[[rule.threat.technique.subtechnique]]
147id = "T1204.002"
148name = "Malicious File"
149reference = "https://attack.mitre.org/techniques/T1204/002/"
150
151[rule.threat.tactic]
152id = "TA0002"
153name = "Execution"
154reference = "https://attack.mitre.org/tactics/TA0002/"
155
156[[rule.threat]]
157framework = "MITRE ATT&CK"
158
159[[rule.threat.technique]]
160id = "T1105"
161name = "Ingress Tool Transfer"
162reference = "https://attack.mitre.org/techniques/T1105/"
163
164[rule.threat.tactic]
165id = "TA0011"
166name = "Command and Control"
167reference = "https://attack.mitre.org/tactics/TA0011/"
168
169[[rule.threat]]
170framework = "MITRE ATT&CK"
171
172[[rule.threat.technique]]
173id = "T1218"
174name = "System Binary Proxy Execution"
175reference = "https://attack.mitre.org/techniques/T1218/"
176
177[[rule.threat.technique.subtechnique]]
178id = "T1218.005"
179name = "Mshta"
180reference = "https://attack.mitre.org/techniques/T1218/005/"
181
182[[rule.threat.technique.subtechnique]]
183id = "T1218.007"
184name = "Msiexec"
185reference = "https://attack.mitre.org/techniques/T1218/007/"
186
187[[rule.threat.technique.subtechnique]]
188id = "T1218.011"
189name = "Rundll32"
190reference = "https://attack.mitre.org/techniques/T1218/011/"
191
192[rule.threat.tactic]
193id = "TA0005"
194name = "Defense Evasion"
195reference = "https://attack.mitre.org/tactics/TA0005/"

Triage and analysis

Investigating Suspicious Execution from VS Code Extension

Malicious VS Code extensions can use activationEvents: ["onStartupFinished"] to run as soon as the editor starts, then spawn scripts or download-and-execute payloads (e.g. weaponized ScreenConnect, batch/PowerShell downloaders). This rule flags process starts whose parent command line indicates execution from the extension host under .vscode\extensions\ (or /.vscode/extensions/).

Possible investigation steps

  • Identify the extension: from the parent process command line, extract the path under .vscode\extensions\ to get the extension id (e.g. publisher.name-version).
  • Check whether that extension is approved; search the VS Code marketplace (or internal registry) for the same name and compare hashes.
  • Inspect the child process: if it is cmd/powershell/curl/node/rundll32/etc., review command line and network/file activity; if it is a recently created executable (e.g. Code.exe, Lightshot), check path (e.g. %TEMP%\Lightshot) and code signature.
  • Correlate with network events (C2 domains, Dropbox/URL downloads) and with Fake Clawdbot VS Code Extension IOCs if relevant.

False positive analysis

  • Legitimate extensions that run scripts or tools (e.g. linters, formatters, task runners) can spawn cmd, node, or PowerShell. Tune by excluding known extension ids or by requiring additional conditions (e.g. outbound to unknown IPs).
  • Extension development: running/debugging an extension from a workspace will spawn processes from .vscode\extensions\; consider excluding dev machines or specific parent paths.

Response and remediation

  • Uninstall the suspicious extension and restart VS Code.
  • If payload was executed: check for ScreenConnect (or similar) installation paths and services, remove persisted artifacts, block IOCs at firewall/DNS, rotate any API keys or secrets that may have been entered into the extension.

References

Related rules

to-top