Open-source atomic malware analysis

Analyze another

enaium.jimmer-buddy-lsp-0.4.0.vsix

VSIX
Verdict: SUSPICIOUS

Objectives

hostile severity, 98% confident.
anti-static/obfuscation/reflection JVM reflection command exec
hostile severity, 95% confident.
command-and-control/channel/deaddrop URL dead drop / indirection pattern
hostile severity, 98% confident.
exfiltration/http Java HTTP data exfiltration
suspicious severity, 100% confident.
anti-analysis/geofencing CIS region timezone offset checks
suspicious severity, 94% confident.
anti-analysis/timing Kotlin Thread.sleep check
suspicious severity, 96% confident.
anti-static/obfuscation/payload Java bytecode Base64 decode to Runtime.exec
suspicious severity, 94% confident.
command-and-control/backdoor/tasking JS execSync command call
suspicious severity, 96% confident.
command-and-control/channel Hardcoded Discord bot token
suspicious severity, 94% confident.
command-and-control/dropper Spawned Python executes stdin payload
suspicious severity, 92% confident.
command-and-control/dropper/execution JVM ProcessBuilder bytecode
suspicious severity, 95% confident.
credential-access/env/secrets DISCORD_TOKEN environment variable access
suspicious severity, 94% confident.
evasion/hijack-execution-flow Node hidden module inject
suspicious severity, 95% confident.
evasion/self-delete/file Java bytecode delayed file deletion
suspicious severity, 94% confident.
execution/compile Java bytecode URLClassLoader
suspicious severity, 94% confident.
exfiltration/stealer/credential Node AWS credential path
suspicious severity, 93% confident.
exfiltration/stealer/host-profile TS collects process and env
suspicious severity, 94% confident.
impact/ransom/encrypt Java locked file extension
suspicious severity, 94% confident.
impact/wipe QNX Node process kill loop
suspicious severity, 93% confident.
persistence/login/shell JVM profile bytecode

Micro-behaviors

suspicious severity, 95% confident.
fs/path/sensitive GitHub CLI authentication hosts file

20 of 291 traits shown

Identity

SHA-256 43fc0dff4445c6ea8fe8b88cd5bc3b84027d07a7a5e4ebd79d2026d8d9784bd2
Canonical SHA-256 0000c51a9d341c509ee62736a86b4e010ca42669f5675cfa67851484e44e93f3
Filename enaium.jimmer-buddy-lsp-0.4.0.vsix
Package enaium
Version 0.4.0

Origin

Source harvest
Feed open-vsx.org
Ecosystem vscode
Domain open-vsx.org

Timeline

First seen 14 Jun 2026 16:59 UTC
First analyzed 14 Jun 2026 18:43 UTC
Last analyzed 14 Jun 2026 18:43 UTC
Last updated 14 Jun 2026 18:43 UTC

Labeling

Label unknown
Label source harvest
Traits version 061e3