Knostic identified four VS Code extensions that reuse malicious code from the SaassyCode family. They reveal two distinct forms of reuse: one package was republished almost unchanged, while three others were rebuilt around reused source code.
Our previous research documented 24 extensions in the SaassyCode family. These four are additional Marketplace listings that reuse SaassyCode code: one republishes an already-documented package, while three reuse the TrelloBlox source. This investigation builds on our original SaassyCode disclosure and our analysis of the post-disclosure wave.
ManageRBLX123 is an almost exact repackaging of ManageRBLX 4.9.5, one of the two extensions in our original June disclosure. Someone changed five lines of metadata and republished the package, dropper and all.
FocusDeck, Trello Deck, and Swimlane represent a different kind of reuse. All three are built on TrelloBlox 5.7.0’s source code, but its original dropper—a remote script written to the temporary directory and executed through Windows Script Host—was removed. Instead, activate() calls a small loader that spawns a detached Node process using the editor’s own binary. That process runs an install script located inside a bundled dependency, which downloads and executes the payload.
That change matters more than the rebranding. The original chain left two clear indicators: a cscript.exe child process and a file named nice.js in %TEMP%. The replacement removes both while preserving the same download-and-execute behavior. The code lineage is confirmed in all four extensions, but that does not establish who repackaged or rebuilt them.
| Extension | Publisher | Version | Installs (observed) | Relationship to SaassyCode |
|---|---|---|---|---|
| ManageRBLX123 | testpublisher610 | 5.0.5 | 0 (7 Aug 2026) | Exact repackaging of ManageRBLX 4.9.5 |
| FocusDeck | BLSoftworks | 1.0.3 | 1,015 (19 Aug 2026) | TrelloBlox 5.7.0 source derivative |
| Trello Deck | TrelloSoftWorks | 1.0.1 | 55 (19 Aug 2026) | TrelloBlox 5.7.0 source derivative |
| Swimlane | StackStudios | 1.0.2-1.0.3 | 1,184 (20 Aug 2026) | TrelloBlox 5.7.0 source derivative |
Install counts are point-in-time Marketplace observations, not confirmed infections. Together, the three source derivatives had 2,254 observed installs across the dates shown.
The diagram shows the two reuse patterns. The left branch preserves ManageRBLX’s original package and execution chain. The right branch preserves TrelloBlox’s application code but replaces its inline dropper with a new loader and dependency-based delivery chain.
The two groups require different evidence. ManageRBLX123 is established through a byte-level comparison of two VSIX archives. The other three are established through source-level comparison with TrelloBlox 5.7.0.
ManageRBLX123 5.0.5 and ManageRBLX 4.9.5 differ by five lines, spread across two metadata files. Six of the eight archive entries are byte-identical, including extension/src/extension.js, the file that carries the dropper.
--- extension/package.json - "displayName": "ManageRBLX", + "displayName": "ManageRBLX12222", - "version": "4.9.5", - "publisher": "GeorgeXBT", + "version": "5.0.5", + "publisher": "testpublisher610", --- extension.vsixmanifest - <Identity Id="managerblx" Version="4.9.5" Publisher="GeorgeXBT" /> - <DisplayName>ManageRBLX</DisplayName> + <Identity Id="managerblx123" Version="5.0.5" Publisher="testpublisher610" /> + <DisplayName>ManageRBLX123</DisplayName>
Because extension.js was untouched, the original execution chain came with it: activate() downloads newly.js from giantapplebees[.]shop, saves it as %TEMP%\nice.js, and executes it with cscript //nologo //e:jscript. The description, activation events, icons, and README were also carried over unchanged. The manifest identity was updated, but the name field in package.json still reads managerblx.
The original package also retained internal TaskBlox identifiers, including the command taskblox.open and the panel ID taskblox-board. These identifiers survived unchanged in ManageRBLX123.
The byte-identical malicious files establish package lineage conclusively, but they do not identify who republished the package. The minimal metadata-only change is consistent with either malicious republishing or a researcher testing whether a known sample would still be detected under a new identity.
Each of the three ships an extension/src/extension.js that is TrelloBlox 5.7.0’s file with 2,263 of its 2,294 lines byte-identical. About a dozen branding strings were changed, the malicious block was removed, and one line was added to call a new loader. The rest — a complete working Kanban webview with its own state model, drag-and-drop, activity feed and JSON export — was carried over as it stood.
The strongest lineage markers are arbitrary implementation details that would be unlikely to appear independently.
rb_workspaces and rb_activeId appear in TrelloBlox and all three derivatives.makeWorkspace('My Game', 'Owner'), a game-development default surviving inside three products that present themselves as generic project planners.FocusDeck carries a command mismatch. Its package.json contributes FocusDeck.open, but the code registers fluxBoard.open and its error text says “Flux Board”. The rebrand reached the manifest and not the source, so the extension’s only user-facing command does not work at all.
TrelloBlox imports child_process and https for its original dropper. All three derivatives retain those now-unused imports. FocusDeck and Trello Deck add require('./patt'), while Swimlane adds require('./package'), which points to its obfuscated package.js loader. These are clear remnants of the original dropper being removed and replaced.
These artefacts were not included in Knostic’s public reporting, so copying our write-ups does not explain the overlap. However, the original VSIX was publicly available, and a third party could have extracted and modified its source.
With the inline dropper removed, delivery moves out of extension.js and into code stored inside a bundled dependency. The extension still initiates the chain through its activate() function.
The first stage is a small loader. FocusDeck and Trello Deck contain a byte-identical plaintext loader at extension/src/patt.js. Swimlane uses an obfuscated implementation of the same loader behavior at extension/src/package.js. Its purpose is to locate an install script inside the bundled dependency and launch it:
const child = spawn(nodeBinary, [installScript], { cwd: path.dirname(installScript), detached: true, stdio: 'ignore', windowsHide: true, env: { ...process.env, ELECTRON_RUN_AS_NODE: '1' } }); child.unref();
The loader sets ELECTRON_RUN_AS_NODE=1, causing the Electron executable used by VS Code to run as a Node.js process. This allows it to execute the bundled install script without requiring a separate Node.js installation. The process is detached, its standard input and output are discarded, and its console window is hidden on Windows.
The script launched by the loader is already packaged inside the VSIX. FocusDeck and Trello Deck bundle a dependency named boardflow, version 1.2.1, whose package.json declares "preinstall": "node install.js". Swimlane contains a closely related bundled dependency named typescripts, also version 1.2.1, which declares "preinstall": "node lolnstall.js".
These dependencies contain extension-specific payload URLs and are delivered inside the VSIX. We therefore found no evidence that their presence resulted from the compromise of an independently maintained upstream npm package.
The declared preinstall hooks are not what triggers execution. No npm install occurs at runtime. Instead, activate() calls the loader directly, and the loader launches the bundled install script.
Each install script contains a small obfuscated downloader built from the same general template. It creates a destination under the temporary directory, uses curl -L -o to retrieve a file, and then executes the downloaded path. Each extension uses a different hard-coded URL and destination filename:
| Extension | Loader | Install script it launches | Payload URL | Staged as |
|---|---|---|---|---|
| FocusDeck 1.0.3 | extension/src/patt.js | boardflow/install.js | hxxp://realism-hub[.]com/NevyP5PQU5wz.bat | %TEMP%\NevyP5PQU5wz.bat |
| Trello Deck 1.0.1 | extension/src/patt.js | boardflow/install.js | hxxp://pixelrbx[.]com/846385d443.bat | %TEMP%\846385d443.bat |
| Swimlane 1.0.2 | extension/src/package.js (obfuscated) | typescripts/lolnstall.js | hxxp://boss67[.]icu/perfect.exe | %TEMP%\4649nadeshiko.exe |
| Swimlane 1.0.3 | extension/src/package.js (obfuscated) | typescripts/lolnstall.js | hxxps://whats-the-time-in-shanghai[.]netlify[.]app/xd[.]exe | %TEMP%\4649nadeshiko.exe |
This replacement chain removes the two specific artifacts associated with the original SaassyCode dropper: it does not launch cscript.exe, and it does not create %TEMP%\nice.js. It introduces a different set of observable files and process behaviors instead.
Code and package lineage is confirmed. ManageRBLX123 preserves the malicious code from ManageRBLX 4.9.5 unchanged, while FocusDeck, Trello Deck and Swimlane reuse TrelloBlox 5.7.0’s source code.
The evidence also supports coordinated packaging of the three TrelloBlox derivatives with high confidence. FocusDeck and Trello Deck contain a byte-identical loader, while Swimlane contains an obfuscated implementation of the same behavior. The three packages bundle closely related dependencies derived from the same template, with extension-specific install scripts and payload URLs. They also share the same obfuscation approach and byte-identical LICENSE.txt and desktop.ini files, providing additional evidence of a shared packaging environment.
What the evidence does not establish is whether the original SaassyCode operator published any of these extensions. The original VSIX files were publicly obtainable, so reuse by a third party remains a reasonable alternative. We therefore attribute the four extensions to the SaassyCode code lineage, but not necessarily to the same operator.
| Extension | Version | VSIX SHA-256 | Payload URL | Staged filename |
|---|---|---|---|---|
| testpublisher610.managerblx123 | 5.0.5 | 83882b3de27d578933a148a809cc459037ce09660c46ef558430cbaaca36d7fe | hxxps://giantapplebees[.]shop/newly.js | %TEMP%\nice.js |
| BLSoftworks.FocusDeck | 1.0.3 | a090fc46a70d94e04d7535ab885a2f74d42f7fb61499167bf01169236a585a4c | hxxp://realism-hub[.]com/NevyP5PQU5wz.bat | %TEMP%\NevyP5PQU5wz.bat |
| TrelloSoftWorks.trello-deck | 1.0.1 | 23a9c3dc9c8df9c5e7c9d36896728d6b29d19d309c4a440741eb45e1194653f2 | hxxp://pixelrbx[.]com/846385d443.bat | %TEMP%\846385d443.bat |
| StackStudios.swimlane | 1.0.2 | b8ba3b10f511fd9b0fe60b4a2e5afb277d4e6fd3d839195be14d966ca407feef | hxxp://boss67[.]icu/perfect.exe | %TEMP%\4649nadeshiko.exe |
| StackStudios.swimlane | 1.0.3 | 108fd1f9d0d5a704ce8e7eec4fbb492fec47e26f0b406af5d70466f30b8d4547 | hxxps://whats-the-time-in-shanghai[.]netlify[.]app/xd[.]exe | %TEMP%\4649nadeshiko.exe |
| Extension | Version | VSIX SHA-256 |
|---|---|---|
| GeorgeXBT.managerblx | 4.9.5 | cfdf72c510670341dce392ab250a5f5ff2a398d993d1106fb8026ec6397cb393 |
| TrelloBlox.TrelloBlox | 5.7.0 | 8852c7fc9c924b0664b0d6466081100011ee3cfe541549c02ef8f921b5d4c9ec |
One extension republished ManageRBLX with five metadata lines changed and its dropper intact. Three more reused the TrelloBlox source and replaced its Windows Script Host dropper with a loader that runs a bundled dependency's install script through the editor's own Node runtime. These samples demonstrate continued reuse and modification of the SaassyCode codebase.