Fake Roblox dev job installs malware through a VS Code extension A write-up of the "Studio Docs" extension (dawngroup.studiodocs-app) Written: 4 October 2026 How this was checked: the extension and every file it downloads were unpacked and read without being run on a real PC. The last file in the chain was also run in three online sandboxes. About the addresses: attacker addresses are written with [.] so nobody clicks them by mistake. Take the brackets out if you need to use them. 1. What happened A Roblox developer got a DM on Discord offering paid work on a popular game. The people behind it looked real. They had a group chat with several "team members", they gave the developer access to a Roblox group for a game with around 3,000 players online, and the developer says they were verified in a well-known developer community. Then they asked for one small thing: install a VS Code extension called Studio Docs to see the task list, and join their board with a code they sent. The developer searched for it on the Marketplace, it came up first, and installed it. That was the attack. Studio Docs is a backdoor. Joining the scammers' board made it download a script and run it in the background. That script pulled down more files, and the chain ended with a hidden program running inside Windows at every logon. All of this happened the day after the developer sold a game. The PC has since been wiped. When that hidden program was run in a sandbox, it connected to 216.107.137[.]77 on port 56001. The way it connects is typical of .NET remote-access tools, the kind that let someone else control a PC, although the exact family is not confirmed. The extension was still on the Marketplace, with about 1,250 installs, when this was written. 2. Who can stop it Who What they can do Microsoft (Visual Studio Marketplace) Take down dawngroup.studiodocs-app and look at the publisher account "dawngroup". It would also help to remove it from machines that already have it, because the extension checks its server every 60 seconds and can be handed a new script at any time. Vercel Take down the three projects the chain depends on: www.canvases[.]work, vibes-effecting[.]vercel[.]app, and lol-five-orpin[.]vercel[.]app. The last one collects status messages about each victim and seems to pass them on somewhere, so its settings may show where. Datacamp Limited (runs the network the server address is on) Look into the server at 216.107.137[.]77. It accepted the malware's connection on TCP port 56001 on 4 October 2026. Discord Look at the accounts in section 5.3, which were used for the fake offer. Some of them are probably stolen. If the Vercel relay forwards to a Discord webhook, delete it. Studio Docs write-up – page 1 Who What they can do Roblox Look at the group and game used as bait. The developer believes the game was stolen from someone else, and that the Roblox accounts used to get verified in the HiddenDevs community were stolen too. 3. How it works 3.1 The extension Studio Docs looks like a simple task board, and the board really works. The problem is what it does behind it. 1. It starts with VS Code. The extension loads every time VS Code opens. 2. It talks to its own server. After an install or update it fetches a "welcome" board from www.canvases[.]work. It checks the server again every 60 seconds, and it fetches any board you join with a code. 3. It runs a hidden field as a script. Each board has a "note". If the note starts with "js:", the extension saves the text into %USERPROFILE%\.studiodocs\hooks\ and runs it with cscript.exe on Windows, or sh on macOS and Linux. Then it deletes the file and clears the note, so nothing is left to see. 4. Its safety switch is fake. The code includes signature checks and a setting called "allow trusted hooks" that is off by default, which looks reassuring. But unsigned scripts still run whenever the board has the creation date 2026-09-11T00:00:00.000Z, and that date comes from the server itself. 3.2 The download chain Step Where it comes from What it does 1 A board called "special-game-dev" on www.canvases[.]work, reached with the join code the scammers sent A scrambled script hidden in the board's note. It downloads step 2 to %TEMP%\b.js and runs it with no window. 2 vibes-effecting[.]vercel[.]app/ pebble_kys.js Downloads step 3 into %TEMP% under a random 10- character .bat name and runs it hidden. It also reports each stage, along with the Windows username and computer name, to lol-five-orpin[.]vercel[.]app. 3 vibes-effecting[.]vercel[.]app/ pxbbzXfFPmhd1.bat A scrambled 802 KB batch file. It checks whether it is being analysed, copies itself to C:\ProgramData\ IntelDriver\VQR.cmd, copies PowerShell to Downloads\bjx.exe, decrypts a PowerShell script hidden inside itself, and sets up a scheduled task. 4 Packed inside the step 3 file The PowerShell script injects a 446 KB encrypted loader into explorer.exe. The loader unpacks a .NET program called Gzlkfmpg.exe, which in turn decrypts and loads one more program from inside itself. One thing worth knowing: the default welcome board had no script on it when it was checked on 4 October 2026. So people who installed the extension but never joined a scammer's board may not Studio Docs write-up – page 2 have been hit. That is not a reason to relax, though. The welcome board already has the date that lets unsigned scripts run, so a script could be added to it at any moment. 3.3 How it hides and stays • It quits if the PC has less than 3 GB of memory, which is common in analysis machines. • It quits if the username is "Admin" and a file called VBE or mapping.csv is in %TEMP%. That matches the Triage sandbox, where the run stopped at exactly this point. • It creates a hidden scheduled task called gRpp, labelled "IntelDriver System Service", that runs at logon and starts everything again. • If it cannot get into explorer.exe, it tries SecurityHealthSystray, OneDrive, sihost, RuntimeBroker, and taskhostw. 3.4 The second extension The developer was also told to install Trello Viewer (Ho-Wan.vscode-trello-viewer, version 0.6.0). That one is clean. Its code only talks to api.trello.com and trello.com, it does not start other programs, nothing in it is scrambled, and its five bundled libraries match the official npm releases byte for byte. It is a genuine extension from 2019, and it was probably mentioned to make the request feel normal. Package SHA-256: df8bcba3f01ac5efc8aebe870eeb46c059f75f627d98940d7d0039e906ede562. 4. What to look for 4.1 Addresses Address What it is www.canvases[.]work The extension's server. Paths: /api/canvases/sync, /api/canvases/share, /api/canvases/hooks/pubkey. Hosted on Vercel. vibes-effecting[.]vercel[.]app Serves step 2 (/pebble_kys.js) and step 3 (/pxbbzXfFPmhd1.bat). lol-five-orpin[.]vercel[.]app Collects the status messages from step 2. They are sent as JSON with a "content" field, which is the format Discord webhooks use. 216.107.137[.]77 TCP port 56001 Where the final program connected in a VirusTotal sandbox run, so most likely its control server. Network: AS212238 Datacamp Limited. TLS certificate SHA-1 thumbprint 2b08823b580a8a9f3f366b17296d7ac4d491e55a. Client JA3 fc54e0d16d9764783542f0146a98b300. timeapi[.]io (a normal service) Step 2 asks it for the time in the America/Detroit zone to timestamp its messages. On 4 October 2026, www.canvases[.]work pointed to 216.198.79.1 and 64.29.17.1 through vercel-dns- 017.com. Those are shared Vercel addresses that plenty of unrelated sites use, so do not block them or treat them as the attackers' own. Studio Docs write-up – page 3 4.2 Files (SHA-256) File SHA-256 The extension, dawngroup.studiodocs- app-0.2.0.vsix 3d64a4accd7cc15934fb9e344eaa1997e35eac97f0c8da670288786d55c69439 Step 3, pxbbzXfFPmhd1.bat (MD5 bfd463fb2e647d10615fcff9 a23a68a7) a5f2373bbbecac16ffe920cd79358a244c956e9f5a63d652484a2dbd41029572 The encrypted loader put into explorer.exe (446,182 bytes, only ever in memory) 7ca85ff35a407d5fbdfb690c8fea04600d2694d3368fbe17e9f3d9329659e44e The unpacked .NET program, Gzlkfmpg.exe (569,856 bytes, only ever in memory) 92dcd7c2af8bd6739a70293b8fa8b123bc9ab0cfc3c656f08819f4a3ebe4317f The last two never show up as files on a victim's disk. Their hashes come from unpacking step 3 and are here for anyone who wants to dig further. 4.3 Signs on an infected PC Where What you would find %USERPROFILE%\.studiodocs\ Saved boards (*.canvas.json), a hooks folder, trusted- hook-key.json %TEMP% b.js, a .bat with a random 10-character name, kj-out-*.log files (the output of scripts the extension ran), stray .ps1 files C:\ProgramData\IntelDriver\ (hidden) VQR.cmd, PoPeK.jpg, PoPeK.ps1, sometimes windows.ps1 %USERPROFILE%\Downloads\bjx.exe (hidden) A copy of the real powershell.exe under another name Task Scheduler A task called "gRpp", described as "IntelDriver System Service", running wscript.exe at logon %LOCALAPPDATA%\gRpp.vbs and %APPDATA%\ gRpp.xml The launcher script and the task definition Running processes code.exe starting cscript.exe, or cmd.exe starting bjx.exe Studio Docs write-up – page 4 5. Evidence 5.1 The Marketplace listing Figure 1. The Studio Docs listing on 4 October 2026: 1,250 installs, version 0.2.0, released 23 September 2026, updated 1 October 2026, and no link to any source code. Listing: https://marketplace.visualstudio.com/items?itemName=dawngroup.studiodocs-app (do not click Install). The version history shows two releases, 0.0.1 on 23 September 2026 and 0.2.0 on 1 October 2026. Inside the package, the author is given as "pulsedigital". 5.2 Sandbox runs of step 3 Figure 2. The ANY.RUN run, marked "Malicious activity". The panel on the right shows schtasks.exe creating the gRpp task from gRpp.xml. Studio Docs write-up – page 5 Sandbox What it showed Link ANY.RUN Marked malicious, tagged "evasion" and "susp-powershell". It confirmed the bjx.exe steps and the scheduled task. The run was only 60 seconds, so it ended before the final program contacted anything. Interactive task Text report Triage Scored 8 out of 10. The file stopped after its first few steps and made no connections, which fits its sandbox check. Behavioural report VirusTotal Only 4 of 61 engines flag it, all with generic names: ESET BAT/Obfuscated.AW, Kaspersky HEUR:Trojan.BAT.Obfus.gen, Ikarus Trojan.BAT.Obfuscated, and Google. Microsoft Defender does not flag it. The Behavior tab shows one outbound connection, TCP 216.107.137[.]77:56001 over TLS. Detection page 5.3 The Discord side This is the first message the developer received. After replying, the developer was added to a group chat of six people and says the people in it were the scammers. Figure 3. The first DM, from an account called "Sarah" (dev_sarah): a commission offer from someone claiming to co-own a game called "meow madness" with 10k players online and a big budget. Display name Username Joined Discord What the profile shows Sarah dev_sarah 28 Apr 2019 Sent the first message. Server tag "dræm". Bio: "General Executive at DreamTeam, Partnered with ForFun Project". Became friends with the developer on 4 Oct 2026. Simon devwithsimon 19 Jan 2023 Server tag "dræm". The bio is identical to Sarah's, word for word. safari safarivanta 5 Aug 2017 Server tag "dræm". A GitHub connection shown as "skill". Friends with the Sarah account. $$ account_327 29 May 2026 Private profile. Friends with the Sarah account. A word of caution about these accounts. Only Sarah is shown sending anything. The other three are listed because they were in the same group chat, and what each of them did is not shown here. Two of the accounts Studio Docs write-up – page 6 are years old, and one has details that do not match (the name Sarah with he/him pronouns). That is what stolen accounts tend to look like, so the real owners may be victims as well. 6. What is still unknown • What the final program can do. Gzlkfmpg.exe is heavily protected and is only a wrapper: it decrypts another program of about 210 KB and runs that. The inner program could not be read. The way it connects looks like AsyncRAT or a similar .NET remote-access tool, but other .NET programs connect the same way, so that is a best guess. • Whether there are more servers. 216.107.137[.]77:56001 showed up in one sandbox run. The other two runs ended too early to show anything. Datacamp address space is often rented out to other hosting and VPN companies, so this may not be the operators' own machine. No Discord or Telegram webhook was found in the final program. • Where the status messages go. Their format points to a Discord webhook behind lol-five- orpin[.]vercel[.]app, but only Vercel can see how that project is set up. • Who is behind it. The only hint is the America/Detroit time lookup, which suggests a US Eastern timezone and proves nothing. • Whether the names are real. The scammers used the names "meow madness", "DreamTeam", "ForFun Project" and, according to the developer, "LockedIn Studio" (Locked.dev). There may be real games or studios with those names being impersonated. Nothing here says they are involved. • What was taken. The developer says a large part of the money from the game sale may be gone. No transaction records were available for this write-up. • Whether this is the SaassyCode campaign. Knostic described a campaign with two other fake extensions, ManageRBLX and TrelloBlox, that also posed as task boards for Roblox work and also had code.exe launching cscript.exe. It looks like the same playbook. That is a resemblance, not proof it is the same people. 7. If you installed it • Assume the PC is compromised. Almost no antivirus catches the step 3 file, so a clean scan tells you nothing. • From a different device, change your passwords (email first), sign out of every session, and turn on two-factor authentication. • Reinstall Windows. Uninstalling the extension and deleting the files in section 4.3 is not enough, because the hidden program could have installed anything. • Check your Roblox groups and games for new admins, changed owners, or missing funds, and revoke any API keys or tokens that were saved on that PC. 8. Links • Knostic on the SaassyCode campaign (ManageRBLX, TrelloBlox) • The Studio Docs listing on the Visual Studio Marketplace • ANY.RUN text report • Triage behavioural report • VirusTotal detection page Studio Docs write-up – page 7