Fake Moltbot AI Extension on VS Code Marketplace Distributes Malware
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Cybersecurity researchers have identified a fake extension for Microsoft Visual Studio Code called ‘ClawdBot Agent – AI Coding Assistant’ that was published on January 27, 2026. This extension, created by a user named ‘clawdbot’, masquerades as a free AI coding assistant but actually installs malware on users’ systems. The malicious payload is executed automatically when the integrated development environment (IDE) is launched, allowing attackers to gain persistent remote access to compromised hosts.
The extension retrieves a configuration file from an external server, which facilitates the execution of a binary named ‘Code.exe’ that deploys a legitimate remote desktop program, ConnectWise ScreenConnect. This setup enables attackers to control compromised systems effectively. Additionally, the extension has a fallback mechanism that retrieves a DLL file from Dropbox to ensure the malware is delivered even if the primary command-and-control infrastructure is unavailable.
Security researcher Jamieson O’Reilly has highlighted the risks associated with the legitimate Moltbot instances, which expose sensitive configuration data, API keys, and conversation histories to unauthorized parties. The Clawdbot agents can impersonate users across various messaging platforms, allowing attackers to inject messages and exfiltrate sensitive data without the user’s knowledge.
Another analysis by Intruder noted widespread misconfigurations leading to credential exposure and vulnerabilities across multiple cloud providers. The core issue lies in the architectural design of Clawdbot, which prioritizes ease of deployment over secure configurations, leaving non-technical users vulnerable.
Implications for Users and Organizations
This incident underscores the importance of vigilance when installing third-party extensions, especially those that claim to be AI tools. Users should be cautious of extensions that do not originate from verified sources, as they may pose significant security risks.
Organizations using Moltbot or similar tools should conduct thorough audits of their configurations, revoke unnecessary service integrations, and monitor for signs of compromise. Implementing strict network controls and validating credentials can help mitigate risks associated with unauthorized access.
As the popularity of AI tools continues to grow, so does the potential for malicious actors to exploit them. Users must remain aware of the security implications of deploying such tools and ensure they follow best practices for cybersecurity.
Key Takeaways
- Audit your configurations if you are using Clawdbot or similar tools to ensure they are secure.
- Revoke any unnecessary service integrations to minimize potential attack vectors.
- Monitor your systems for signs of compromise, especially if you have installed third-party extensions.
- Implement strict network controls to limit unauthorized access to sensitive data.
- Be cautious when installing extensions from unverified sources, particularly those claiming to be AI tools.
Key Terms & Concepts
- Moltbot: In this article, Moltbot refers to an open-source AI assistant project that allows users to run a personal AI assistant locally.
- ScreenConnect: ScreenConnect is a remote desktop program that allows users to access and control computers remotely.
- DLL: A DLL, or Dynamic Link Library, is a file that contains code and data that can be used by multiple programs simultaneously.
- Command-and-Control (C2): C2 refers to the infrastructure used by attackers to control compromised systems and deliver malicious payloads.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.