Nextron Research analyzed two malicious VS Code extensions distributed as Trello Board by publisher TrelloWorks and Trello Deck by publisher TrelloSoftWorks. The extensions are Windows-focused, multi-stage loader consistent with the SaassyCode campaign documented by Knostic.
Related research: https://www.knostic.ai/blog/new-vs-code-extensions-attack-campaign-saassycode-managerblx-trelloblox
The extensions activate automatically when VS Code finishes starting. They launch an obfuscated installer from its bundled boardflow dependency in a hidden, detached process. The installer downloads and executes a BAT payload over unencrypted HTTP.