Malicious VS Code extension "Studio Docs" Incident and abuse report: dawngroup.studiodocs-app Date of analysis: 4 October 2026 Method: static analysis of the extension package and each downloaded stage (nothing was run on a real machine), plus three public sandbox submissions. The static analysis was done with Claude, an AI assistant. Note on addresses: attacker addresses are written with [.] so they cannot be clicked by accident. Remove the brackets to use them. 1. Summary The Visual Studio Code extension "Studio Docs" (publisher Dawn Group, ID dawngroup.studiodocs- app, version 0.2.0) is a backdoor. It presents itself as a team task board, but it downloads a script from its own server and runs it on the user's PC through Windows Script Host. It was still listed on the Visual Studio Marketplace, with about 1,250 installs, when this report was written. The extension is being used in a fake job offer scam aimed at Roblox developers. The victim was contacted on Discord with a paid commission offer, given access to a Roblox group to make the offer look real, and told to search the Marketplace for "Studio Docs", install it, and join the scammers' board with a join code "to track tasks". The victim says the extension appeared at the top of the search results. Joining that board delivered a script that started a four-stage download chain. The chain ends with an encrypted program injected into explorer.exe and a hidden scheduled task that restarts it at every logon. The final program is encrypted and its purpose and command server could not be recovered. Tooling built this way is normally a data stealer or remote-access tool, and the victim's accounts should be treated as compromised. The victim has since reset the PC. 2. Action requested Recipient Request Microsoft (Visual Studio Marketplace) Remove dawngroup.studiodocs-app and review the publisher account "dawngroup". Consider uninstalling it from existing users, since it polls its server every 60 seconds and can receive new scripts at any time. Vercel Take down the three projects used in the chain: www.canvases[.]work, vibes- effecting[.]vercel[.]app, and lol-five-orpin[.]vercel[.]app. The last one receives victim status reports and appears to relay them onward, so its configuration may show where they go. Discord Act on the accounts listed in section 5.3, which were used for the fake job offer. Some may be stolen accounts. If the relay above forwards to a Discord webhook, delete that webhook. Roblox Review the group and game used as bait. The victim says the scammers gave access to a group for a game with about 3,000 concurrent players, which the victim believes was stolen from another developer, and that they passed verification in the HiddenDevs community with what were probably stolen Roblox accounts. Studio Docs incident report – page 1 3. How the attack works 3.1 The extension 1. It starts with VS Code. The package declares the activation event onStartupFinished, so its code runs every time VS Code opens. 2. It contacts its server. On each install or update it requests a "welcome canvas" from www.canvases[.]work. It also polls the server every 60 seconds, and it fetches any board the user joins with a join code. 3. It runs the board's "note" as a script. If a board's joinNote field starts with "js:", the text is saved to %USERPROFILE%\.studiodocs\hooks\ and run with cscript.exe (or sh on macOS and Linux). The script file is deleted afterwards and the note is wiped from the saved board. 4. Its safety checks do not apply. The package contains signature-verification code and a setting, "allow trusted hooks", that is off by default. Unsigned scripts still run when the board carries the creation date 2026-09-11T00:00:00.000Z, a value the server supplies itself. 3.2 The download chain Stage Source What it does 1 Board "special-game-dev" on www.canvases[.]work, reached with a join code the scammers gave the victim Obfuscated script in the board's joinNote. Downloads stage 2 to %TEMP%\b.js and runs it hidden with cscript. 2 vibes-effecting[.]vercel[.]app/ pebble_kys.js Downloads stage 3 to %TEMP% under a random 10- character .bat name and runs it hidden. Sends status messages, labelled with the Windows username and computer name, to lol-five-orpin[.]vercel[.]app. 3 vibes-effecting[.]vercel[.]app/ pxbbzXfFPmhd1.bat Obfuscated 802 KB batch file. Checks for sandboxes, copies itself to C:\ProgramData\IntelDriver\ VQR.cmd, copies PowerShell to Downloads\bjx.exe, decrypts an embedded PowerShell script (AES), and creates the scheduled task. 4 Embedded in the stage 3 file The PowerShell script injects a 446 KB encrypted loader into explorer.exe. The loader unpacks a .NET program named Gzlkfmpg.exe, which decrypts and loads one further program from its own resources. The welcome board (system-welcome-canvas) carried no script when it was checked on 4 October 2026, so ordinary installs may not have received a payload. It does carry the creation date that permits unsigned scripts, which means the operators could add one at any time. 3.3 Evasion and persistence in stage 3 • Exits if the PC has less than 3 GB of memory. • Exits if the username is "Admin" and a file named VBE or mapping.csv exists in %TEMP%. The Triage sandbox run stopped at this point. • Creates a hidden scheduled task named gRpp, described as "IntelDriver System Service", that runs at logon. It launches wscript.exe on a .vbs file, which starts VQR.cmd again. Studio Docs incident report – page 2 • If explorer.exe cannot be injected, it tries SecurityHealthSystray, OneDrive, sihost, RuntimeBroker, and taskhostw. 3.4 The second extension sent to the victim The victim was also told to install Trello Viewer (Ho-Wan.vscode-trello-viewer, version 0.6.0). Its package was examined and no malicious code was found. Its own code contacts only api.trello.com and trello.com, it starts no other programs, it is not obfuscated, and its five bundled libraries are byte-identical to the official npm releases. It appears to be a genuine extension from 2019 that the scammers included to make the request look normal. Package SHA-256: df8bcba3f01ac5efc8aebe870eeb46c059f75f627d98940d7d0039e906ede562. 4. Indicators 4.1 Network Address Role www.canvases[.]work Extension server. Paths: /api/canvases/sync, /api/canvases/share, /api/canvases/hooks/pubkey. Hosted on Vercel. vibes-effecting[.]vercel[.]app Hosts stage 2 (/pebble_kys.js) and stage 3 (/pxbbzXfFPmhd1.bat). lol-five-orpin[.]vercel[.]app Receives status reports from stage 2 as JSON with a "content" field, the format Discord webhooks use. timeapi[.]io (legitimate service) Stage 2 looks up the time for the zone America/Detroit to timestamp its reports. On 4 October 2026, www.canvases[.]work resolved through vercel-dns-017.com to 216.198.79.1 and 64.29.17.1. These are shared Vercel addresses used by many unrelated sites, so they should not be blocked or treated as attacker-owned. 4.2 Files and hashes (SHA-256) Item SHA-256 Extension package, dawngroup.studiodocs- app-0.2.0.vsix 3d64a4accd7cc15934fb9e344eaa1997e35eac97f0c8da670288786d55c69439 Stage 3, pxbbzXfFPmhd1.bat (MD5 bfd463fb2e647d10615fcff9 a23a68a7) a5f2373bbbecac16ffe920cd79358a244c956e9f5a63d652484a2dbd41029572 Encrypted loader injected into explorer.exe (memory only, 446,182 bytes) 7ca85ff35a407d5fbdfb690c8fea04600d2694d3368fbe17e9f3d9329659e44e Unpacked .NET program, Gzlkfmpg.exe (memory only, 569,856 bytes) 92dcd7c2af8bd6739a70293b8fa8b123bc9ab0cfc3c656f08819f4a3ebe4317f Studio Docs incident report – page 3 The last two items never exist as files on a victim's disk. Their hashes come from unpacking the stage 3 file and are included for analysts. 4.3 Traces on an infected PC Location What to look for %USERPROFILE%\.studiodocs\ Saved boards (*.canvas.json), a hooks folder, trusted- hook-key.json %TEMP% b.js, a .bat with a random 10-character name, kj-out-*.log (output of scripts the extension ran), stray .ps1 files C:\ProgramData\IntelDriver\ (hidden) VQR.cmd, PoPeK.jpg, PoPeK.ps1, possibly windows.ps1 %USERPROFILE%\Downloads\bjx.exe (hidden) A renamed copy of the genuine powershell.exe Task Scheduler Task "gRpp", description "IntelDriver System Service", runs wscript.exe at logon %LOCALAPPDATA%\gRpp.vbs and %APPDATA%\ gRpp.xml Launcher script and task definition Process behaviour code.exe starting cscript.exe; cmd.exe starting bjx.exe 5. Evidence 5.1 Marketplace listing Figure 1. The Studio Docs listing on 4 October 2026: 1,250 installs, version 0.2.0, released 23 September 2026, last updated 1 October 2026, and no source repository link. Listing: https://marketplace.visualstudio.com/items?itemName=dawngroup.studiodocs-app (do not click Install). Version history shows two releases: 0.0.1 on 23 September 2026 and 0.2.0 on 1 October 2026. The package's author field is "pulsedigital". Studio Docs incident report – page 4 5.2 Sandbox runs of stage 3 Figure 2. ANY.RUN task: verdict "Malicious activity". The process details panel shows schtasks.exe creating the gRpp task from gRpp.xml. Service Result Link ANY.RUN Malicious activity; tags evasion, susp-powershell. Confirmed the bjx.exe steps and the scheduled task. The 60-second run ended before any attacker traffic appeared. Interactive task Text report Triage Score 8/10. The sample stopped after its first steps and made no network requests, consistent with its sandbox check. Behavioural report VirusTotal 4 of 61 engines, all generic: ESET BAT/Obfuscated.AW, Kaspersky HEUR:Trojan.BAT.Obfus.gen, Ikarus Trojan.BAT.Obfuscated, Google. Microsoft Defender did not detect it. Detection page 5.3 Discord accounts and messages The screenshot below shows the first message the victim received. The table lists four members of the six-person group chat the victim was then added to. The victim identifies the people in this chat as the scammers. Studio Docs incident report – page 5 Figure 3. First contact from the account "Sarah" (dev_sarah): a commission offer claiming co-ownership of a game called "meow madness" with 10k concurrent players and a large budget. Display name Username Member since Notes from the profile Sarah dev_sarah 28 Apr 2019 Sent the first message. Server tag "dræm". Bio: "General Executive at DreamTeam, Partnered with ForFun Project". Friends with the victim since 4 Oct 2026. Simon devwithsimon 19 Jan 2023 Server tag "dræm". Bio is word-for-word the same as Sarah's. safari safarivanta 5 Aug 2017 Server tag "dræm". GitHub connection shown as "skill". Mutual friend with the Sarah account. $$ account_327 29 May 2026 Private profile. Mutual friend with the Sarah account. Only the Sarah account is shown sending a message. The other three are included because they were in the same group chat; their individual roles are not shown in the evidence. Two accounts are several years old and one profile has mismatched details (the name Sarah with he/him pronouns), which is consistent with hijacked accounts, so the real owners may also be victims. 6. What is not known • What the final program does. Gzlkfmpg.exe is protected by an obfuscator and contains no networking functions of its own. It decrypts a further program of about 210 KB from its resources, and that program could not be read. • The command server or webhook. No address for the final payload was found in any layer, and no sandbox run lasted long enough to record one. Studio Docs incident report – page 6 • Where the status reports end up. The message format suggests a Discord webhook behind lol- five-orpin[.]vercel[.]app, but that is an inference. Only Vercel can see the project's configuration. • Who is behind it. The America/Detroit time lookup is a weak hint at a US Eastern timezone and nothing more. • Whether the names used are real. The scammers used the names "meow madness", "DreamTeam", "ForFun Project", and, according to the victim, "LockedIn Studio" (Locked.dev). Real games or studios with these names may be being impersonated, and nothing in this report shows they are involved. • What was taken. The victim says the attack came the day after selling a game and that a large part of the money may be gone. No transaction records were available for this report. • Whether it is the SaassyCode campaign. The lure (a task board for Roblox work) and the code.exe to cscript.exe behaviour match the campaign Knostic described, which used the extensions ManageRBLX and TrelloBlox. The link is a similarity, not a confirmed attribution. 7. Advice for anyone who installed it • Treat the PC as compromised. Most antivirus products do not detect the stage 3 file, so a clean scan does not mean the PC is clean. • From a different device, change passwords (email first), sign out all sessions, and turn on two- factor authentication. • Reinstall Windows. Removing the extension and the files in section 4.3 is not enough, because the injected program could have installed more. • Check Roblox groups and games for changed ownership, new admins, or missing funds, and revoke any API keys or tokens stored on that PC. 8. References • Knostic: SaassyCode campaign (ManageRBLX, TrelloBlox) • Visual Studio Marketplace listing for Studio Docs • ANY.RUN text report • Triage behavioural report • VirusTotal detection page Studio Docs incident report – page 7