Count Dooku
Supply-chain campaign that re-published legitimate VS Code extensions to Open VSX with a malicious JavaScript IIFE appended after the source-map comment — placed outside the source map so casual review and diff tools miss it. The injected payload beacons to a hard-coded C2. Tracked by opensourcemalware.com.
What happened
Count Dooku is a supply-chain campaign that takes legitimate, popular VS Code
extensions and re-publishes them to Open VSX under
throwaway publisher namespaces. The re-published package is byte-for-byte the
real extension with one change: a malicious JavaScript IIFE appended to the
bundled extension.js after the //# sourceMappingURL= comment.
Putting the payload after the source-map reference is the whole trick. The
legitimate code, its source map, and every line a reviewer would diff against
the upstream package all appear normal — the injected block sits past the point
where most people (and many automated diff tools) stop reading. On activation
the payload beacons to a hard-coded C2 (https://beststats.world/ping).
Because the carrier is a genuine, useful extension, static reputation and
"does it work?" checks pass cleanly — which is exactly why our own conservative
scorer initially rated many of these LOW. They were surfaced by
cross-referencing the opensourcemalware.com
community threat feed against our catalog.
Why it matters
Open VSX has no publisher-identity verification comparable to the Microsoft
Marketplace, so an attacker can stand up 25+ disposable namespaces and mirror
the most-installed extensions faster than takedowns land. Anyone whose editor
(Cursor, Windsurf, VSCodium, Gitpod, and other VS Code forks default to Open
VSX) resolves these names pulls the trojanized build.
How to spot it
The signature is structural, not string-based:
- A bundled JS file (
extension.js/dist/*.js) has executable code after
its//# sourceMappingURL=trailer — a source map is supposed to be the
last thing in the file. - That trailing block is a self-invoking function (
(function(){…})()/(()=>{…})()) containing network egress (fetch/https.request/XMLHttpRequest)
to a domain absent from the extension's declared functionality. - The package is a near-exact copy of a more-installed extension published
under a different, low-reputation Open VSX namespace.
See the detection proposal filed with this campaign for the YARA rule and the
scoring change.
Affected extensions (45)
| Name | Store | ID | Malicious version | Archived |
|---|---|---|---|---|
| pokemon-pets View analysis | openvsx | Anasfiguigui.pokemon-pets | 1.3.0 | no |
| codebuddy-ai View analysis | openvsx | CodebuddyAI.codebuddy-ai | 1.7.0 | no |
| dadroit-json-generator View analysis | openvsx | Dadroit.dadroit-json-generator | 1.2.2 | no |
| csv-excel-viewer View analysis | openvsx | Development42.csv-excel-viewer | 1.9.0 | no |
| competitive-programming-helper View analysis | openvsx | DivyanshuAgrawal.competitive-programming-helper | 2026.6.1780853884 | no |
| doubao-app-share-vscode-plugin View analysis | openvsx | Doubao.doubao-app-share-vscode-plugin | 0.1.2 | no |
| html-preview-pro View analysis | openvsx | GingerTurtle.html-preview-pro | 1.1.0 | no |
| kimi-vscode View analysis | openvsx | Kingleo.kimi-vscode | 0.0.6 | no |
| claude-color-theme View analysis | openvsx | Lumidew.claude-color-theme | 0.0.6 | no |
| vscode-paste-and-indent View analysis | openvsx | Rubymaniac.vscode-paste-and-indent | 0.0.8 | no |
| docxreader View analysis | openvsx | ShahilKumar.docxreader | 1.4.2 | no |
| Document-Viewer-VSCode-Extensions View analysis | openvsx | SyncfusionInc.Document-Viewer-VSCode-Extensions | 4.0.4 | no |
| open-excel View analysis | openvsx | TomRileyTech.open-excel | 0.0.1 | no |
| vscode-1c-metadata-viewer View analysis | openvsx | Zerobig.vscode-1c-metadata-viewer | 0.2.3 | no |
| gemini-cli-launcher View analysis | openvsx | acebunny00.gemini-cli-launcher | 0.1.0 | no |
| node-essentials View analysis | openvsx | afractal.node-essentials | 1.1.0 | no |
| a-file-icon-vscode View analysis | openvsx | atommaterial.a-file-icon-vscode | 2.0.1 | no |
| markitdown-vscode View analysis | openvsx | bioinfo.markitdown-vscode | 0.3.1 | no |
| vscode-ripgrep View analysis | openvsx | bokuweb.vscode-ripgrep | 0.2.2 | no |
| vscode-deepseek View analysis | openvsx | colourafredi.vscode-deepseek | 1.6.2 | no |
| pptx-preview View analysis | openvsx | corotata.pptx-preview | 1.0.1 | no |
| sql-server-profiler-tool View analysis | openvsx | epolicardo.sql-server-profiler-tool | 0.5.1 | no |
| vscode-fabric View analysis | openvsx | fabric.vscode-fabric | 0.39.18 | no |
| hostinger-connector View analysis | openvsx | hostinger-official.hostinger-connector | 1.2.3 | no |
| web-viewer View analysis | openvsx | hss.web-viewer | 0.0.2 | no |
| node-runner View analysis | openvsx | huanent.node-runner | 1.0.2 | no |
| claude-commit View analysis | openvsx | juajnnlb.claude-commit | 1.0.4 | no |
| claude-commit View analysis | openvsx | juanlb.claude-commit | 1.0.1 | no |
| plan-uml View analysis | openvsx | justuskarlsson.plan-uml | 0.0.8 | no |
| protobuf View analysis | openvsx | kangping.protobuf | 1.1.6 | no |
| vscode-openrouter-extension View analysis | openvsx | khaled.vscode-openrouter-extension | 0.5.0 | no |
| yaml-with-script View analysis | openvsx | matthiesen-technology.yaml-with-script | 1.1.3 | no |
| Lisp View analysis | openvsx | mattn.Lisp | 0.1.12 | no |
| streamlit-preview View analysis | openvsx | mjethwa-streamlit.streamlit-preview | 3.3.4 | no |
| csv-to-table View analysis | openvsx | phplasma.csv-to-table | 1.4.1 | no |
| vscode-playwright-test-runner View analysis | openvsx | sakamoto66.vscode-playwright-test-runner | 1.4.1 | no |
| json-server View analysis | openvsx | sarthikbhat.json-server | 0.0.4 | no |
| md-editor View analysis | openvsx | seepine.md-editor | 0.1.1 | no |
| bazel-vscode View analysis | openvsx | sfdc-eng.bazel-vscode | 0.26.106021821 | no |
| office-editor View analysis | openvsx | shubhamprajapati1202.office-editor | 1.0.1 | no |
| markdown-pdf-plus View analysis | openvsx | tom-latham.markdown-pdf-plus | 1.1.0 | no |
| cursor-ai View analysis | openvsx | vbrocket.cursor-ai | 0.2.0 | no |
| vscode-ollama View analysis | openvsx | warm3snow.vscode-ollama | 1.2.1 | no |
| obsidian-md-vsc View analysis | openvsx | willasm.obsidian-md-vsc | 1.3.0 | no |
| luahelper View analysis | openvsx | yinfei.luahelper | 0.2.29 | no |
Indicators of compromise (5)
| url | https://beststats.world/ping | C2 beacon endpoint reached by the appended payload | |
| domain | beststats.world | Count Dooku C2 domain | |
| ext_id | openvsx-namespace:a373083284542 | Attacker Open VSX publisher namespace (multi-extension) | |
| ext_id | openvsx-namespace:henry-davis-5045 | Attacker Open VSX publisher namespace | |
| ext_id | openvsx-namespace:dwells3532 | Attacker Open VSX publisher namespace |