Skip to content

Instantly share code, notes, and snippets.

View marius-benthin's full-sized avatar

Marius Benthin marius-benthin

View GitHub Profile
@marius-benthin
marius-benthin / iocs.txt
Last active August 11, 2026 07:54
XWorm
Studio-Co/trelloboardv2
a157ffec8c799caaca37f5a8ec3ea48891fb5662294f6ed5652dac3b5ab494f1 (v1.5.2)
bcc3e1e60fd6ee7f7b1bc4846904aa66ff0f3cf113333daae894081e82589d53 (v1.5.1)
Microco/trelloboarda
461ffa8d19e18a01216af0c534401d147c062c56f2857c9e78fccc137d22d61c (1.6.0)
cf92da596a4f0a7193271fee17d15e60182d49babb7710750a6da2d7ed04c114 (1.5.8)
dfdb4b286f172092e7e91ee5335b2fa5d683e80adc54e9300450a4da147c7cc0 (1.5.7)
b42e669627a349fa3a3536a0ad1fee92601f18a2a179f8bfd577173cfce5f938 (1.5.6)
@marius-benthin
marius-benthin / iocs.md
Last active August 13, 2026 06:04
SaassyCode

Malicious VS Code Extensions: TrelloWorks.trello-board and TrelloSoftWorks.trello-deck (SaassyCode)

Nextron Research analyzed two malicious VS Code extensions distributed as Trello Board by publisher TrelloWorks and Trello Deck by publisher TrelloSoftWorks. The extensions are Windows-focused, multi-stage loader consistent with the SaassyCode campaign documented by Knostic.

Related research: https://www.knostic.ai/blog/new-vs-code-extensions-attack-campaign-saassycode-managerblx-trelloblox

Summary

The extensions activate automatically when VS Code finishes starting. They launch an obfuscated installer from its bundled boardflow dependency in a hidden, detached process. The installer downloads and executes a BAT payload over unencrypted HTTP.

@marius-benthin
marius-benthin / iocs.md
Created August 20, 2026 08:41
Malicious Rust crates proc-macro1 and proc-macro-en: Analysis and IOCs

Malicious Rust crates proc-macro1 and proc-macro-en: Analysis and IOCs

Summary

Two malicious Rust crates—proc-macro1 version 1.0.107 and proc-macro-en version 1.0.10—impersonate the naming, source, authorship, and metadata of the legitimate proc-macro2 ecosystem.

Both contain the same malicious build.rs, byte for byte. Building either crate directly or as a transitive dependency downloads and launches a platform-specific payload. Commands that may trigger execution include cargo build, cargo check, and cargo test.

The build script:

@marius-benthin
marius-benthin / iocs.md
Created August 27, 2026 16:52
@testrelic/playwright-analytics@2.13.0
@testrelic/playwright-analytics@2.13.0
│
├─ npm executes scripts/postinstall.cjs
│  SHA-256:
│  19795496ad752f37b76a2dd5d6c6a2914ab6fa62bda0bda7bfe5cd4afd9f029f
│
├─ Hidden code after whitespace is decoded and executed
│  Decoded-loader SHA-256:
│  0d91fd2c87904ab651a0b5673ecd83a6dc9e8bfcb9bc640b65b39f713c6d8a82