The ETHcode VS Code Extension Supply Chain Attack

Updated 5 Oct 2026 · Incident date 17 Jun 2025 · IDE extension

PackageEthcode (7finney) 0.4.x -> 0.5.0 (fixed in 0.5.1, published 1 Jul 2025)
Filepackage.json

ETHcode version 0.5.0 for VS Code shipped with a fake dependency named keythereum-utils. That package starts a hidden PowerShell process that downloads and runs a batch script. Version 0.5.1 removes it.

The attacker did not steal an account. They sent a pull request that the project accepted. Two lines of code in a large change did the harm.

What happened

A malicious pull request added a look-alike dependency to the ETHcode extension, and the project merged it. ReversingLabs reports that the request came on 17 June 2025. The GitHub account that sent it, Airez299, was created the same day and had no earlier activity.

SecurityOnline gives the title of the request as "Modernize codebase with viem integration and testing framework". The request held 43 commits and about 4,000 lines of changes. The harmful part was two lines. One line added the package keythereum-utils to package.json. Its name copies the real keythereum package with -utils added. The second line called require() to load it when the extension starts.

The obfuscated code in keythereum-utils starts a hidden PowerShell process. That process downloads a batch script from a public file-hosting service and runs it. The researchers say the purpose of the second stage is still under investigation. They suggest it targets crypto assets on the victim machine or the Ethereum contracts under development.

The Hacker News reports about 6,000 installs of the extension and 495 downloads of the malicious npm package. The attacker uploaded the package versions between 17 and 21 June 2025.

Microsoft removed the extension from the Marketplace on 26 June 2025. The maintainers then removed the dependency and published 0.5.1 on 1 July 2025. ReversingLabs disclosed the incident on 9 July 2025.

Affected versions

Indicators of compromise

How to check

Read the installed version of the extension and search its files for the fake dependency.

code --list-extensions --show-versions | grep -i ethcode
grep -rl "keythereum-utils" ~/.vscode/extensions/*ethcode*/ 2>/dev/null

A version of 0.5.0 or a file match means the bad build is present. Check your project lockfiles too, because the fake package is also a plain npm package.

What to do now

  1. Update ETHcode to 0.5.1 or later.
  2. Remove keythereum-utils from any project that lists it.
  3. On a machine that ran 0.5.0, check for unknown PowerShell activity and downloaded batch files. Treat the machine as compromised if you find any.
  4. Move crypto assets and rotate private keys and tokens that the machine held.
  5. Review new dependencies in every pull request. Check the history of the contributor who adds them.
  6. Vigilance compares a new extension version with the one you trust and reports the file that gained a new capability. Here, package.json gained a dependency that opens a hidden shell and downloads a program.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Ethcode-prev --new Ethcode-current
files scanned: 32

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.json
           It now downloads from the internet and runs other programs. It did not before.

Frequently asked questions

Which ETHcode version was compromised?

ETHcode 0.5.0 for VS Code. Version 0.5.1, published on 1 July 2025, removes the malicious dependency.

How was the ETHcode extension compromised?

An attacker sent a large pull request that added a fake dependency named keythereum-utils and one line that loaded it. The project merged the request.

What does keythereum-utils do?

It starts a hidden PowerShell process that downloads and runs a batch script from a public file-hosting service.

How do I check if I have the compromised ETHcode extension?

Run code --list-extensions --show-versions and look for ethcode 0.5.0. Then search the extension folder for keythereum-utils.

Sources

  1. reversinglabs.com/blog/malicious-pull-request-infects-vscode-extension
  2. thehackernews.com/2025/07/malicious-pull-request-infects-6000.html
  3. securityonline.info/vs-code-ethcode-extension-hacked-just-2-lines-of-code-led-to-supply-chain-compromise-via-github-pr/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free