### SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain

24 August 2026

### CodeRelay: 12 VS Code Extensions Disguised as Developer Tools

4 August 2026

### Introducing AgentMesh Access Tiers: Building Together, Growing Together

27 July 2026

### Lessons Learned from the Hugging Face Security Team

24 July 2026

- SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain

# SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain

by [Tamir Isaschar](/content/blog/author/tamil-isaschar/index.html)  
24 August 2026

5 mins read

Knostic identified four VS Code extensions that reuse malicious code from the SaassyCode family. They reveal two distinct forms of reuse: one package was republished almost unchanged, while three others were rebuilt around reused source code.

Our previous research documented 24 extensions in the SaassyCode family. These four are additional Marketplace listings that reuse SaassyCode code: one republishes an already-documented package, while three reuse the TrelloBlox source. This investigation builds on our [original SaassyCode disclosure](/content/blog/new-vs-code-extensions-attack-campaign-saassycode-managerblx-trelloblox/index.html) and our analysis of the [post-disclosure wave](/content/blog/saassycode-post-disclosure-wave-five-new-extensions-32000-total-installs/index.html).

**ManageRBLX123** is an almost exact repackaging of ManageRBLX 4.9.5, one of the two extensions in our original June disclosure. Someone changed five lines of metadata and republished the package, dropper and all.

**FocusDeck**, **Trello Deck**, and **Swimlane** represent a different kind of reuse. All three are built on TrelloBlox 5.7.0’s source code, but its original dropper—a remote script written to the temporary directory and executed through Windows Script Host—was removed. Instead, `activate()` calls a small loader that spawns a detached Node process using the editor’s own binary. That process runs an install script located inside a bundled dependency, which downloads and executes the payload.

That change matters more than the rebranding. The original chain left two clear indicators: a `cscript.exe` child process and a file named `nice.js` in `%TEMP%`. The replacement removes both while preserving the same download-and-execute behavior. The code lineage is confirmed in all four extensions, but that does not establish who repackaged or rebuilt them.

## Extensions at a glance

| Extension | Publisher | Version | Installs (observed) | Relationship to SaassyCode |
| --- | --- | --- | --- | --- |
| [ManageRBLX123](https://agentmesh.knostic.ai/extensions/1470266?hash=83882b3de27d578933a148a809cc459037ce09660c46ef558430cbaaca36d7fe) | testpublisher610 | 5.0.5 | 0 (7 Aug 2026) | Exact repackaging of ManageRBLX 4.9.5 |
| [FocusDeck](https://agentmesh.knostic.ai/extensions/1214922?hash=a090fc46a70d94e04d7535ab885a2f74d42f7fb61499167bf01169236a585a4c) | BLSoftworks | 1.0.3 | 1,015 (19 Aug 2026) | TrelloBlox 5.7.0 source derivative |
| [Trello Deck](https://agentmesh.knostic.ai/extensions/1861056?hash=23a9c3dc9c8df9c5e7c9d36896728d6b29d19d309c4a440741eb45e1194653f2) | TrelloSoftWorks | 1.0.1 | 55 (19 Aug 2026) | TrelloBlox 5.7.0 source derivative |
| [Swimlane](https://agentmesh.knostic.ai/extensions/2454630?hash=108fd1f9d0d5a704ce8e7eec4fbb492fec47e26f0b406af5d70466f30b8d4547) | StackStudios | 1.0.2-1.0.3 | 1,184 (20 Aug 2026) | TrelloBlox 5.7.0 source derivative |

Install counts are point-in-time Marketplace observations, not confirmed infections. Together, the three source derivatives had 2,254 observed installs across the dates shown.

## Lineage and execution flow

The diagram shows the two reuse patterns. The left branch preserves ManageRBLX’s original package and execution chain. The right branch preserves TrelloBlox’s application code but replaces its inline dropper with a new loader and dependency-based delivery chain.

## How we established the SaassyCode connection

The two groups require different evidence. ManageRBLX123 is established through a byte-level comparison of two VSIX archives. The other three are established through source-level comparison with TrelloBlox 5.7.0.

### ManageRBLX123: exact repackaging

ManageRBLX123 5.0.5 and ManageRBLX 4.9.5 differ by five lines, spread across two metadata files. Six of the eight archive entries are byte-identical, including `extension/src/extension.js`, the file that carries the dropper.

```
--- extension/package.json - "displayName": "ManageRBLX", + "displayName": "ManageRBLX12222", - "version": "4.9.5", - "publisher": "GeorgeXBT", + "version": "5.0.5", + "publisher": "testpublisher610",  --- extension.vsixmanifest - <Identity Id="managerblx" Version="4.9.5" Publisher="GeorgeXBT" /> - <DisplayName>ManageRBLX</DisplayName> + <Identity Id="managerblx123" Version="5.0.5" Publisher="testpublisher610" /> + <DisplayName>ManageRBLX123</DisplayName>
```

Because `extension.js` was untouched, the original execution chain came with it: `activate()` downloads `newly.js` from giantapplebees[.shop], saves it as `%TEMP%\nice.js`, and executes it with `cscript //nologo //e:jscript`. The description, activation events, icons, and README were also carried over unchanged. The manifest identity was updated, but the `name` field in `package.json` still reads `managerblx`.

The original package also retained internal TaskBlox identifiers, including the command `taskblox.open` and the panel ID `taskblox-board`. These identifiers survived unchanged in ManageRBLX123.

The byte-identical malicious files establish package lineage conclusively, but they do not identify who republished the package. The minimal metadata-only change is consistent with either malicious republishing or a researcher testing whether a known sample would still be detected under a new identity.

### ManageRBLX123: original delivery chain

### FocusDeck, Trello Deck and Swimlane: TrelloBlox source reuse

Each of the three ships an `extension/src/extension.js` that is TrelloBlox 5.7.0’s file with 2,263 of its 2,294 lines byte-identical. About a dozen branding strings were changed, the malicious block was removed, and one line was added to call a new loader. The rest — a complete working Kanban webview with its own state model, drag-and-drop, activity feed and JSON export — was carried over as it stood.

The strongest lineage markers are arbitrary implementation details that would be unlikely to appear independently.

- The arbitrary global-state keys `rb_workspaces` and `rb_activeId` appear in TrelloBlox and all three derivatives.
- The default board is created by `makeWorkspace('My Game', 'Owner')`, a game-development default surviving inside three products that present themselves as generic project planners.

FocusDeck carries a command mismatch. Its `package.json` contributes `FocusDeck.open`, but the code registers `fluxBoard.open` and its error text says “Flux Board”. The rebrand reached the manifest and not the source, so the extension’s only user-facing command does not work at all.

TrelloBlox imports `child_process` and `https` for its original dropper. All three derivatives retain those now-unused imports. FocusDeck and Trello Deck add `require('./patt')`, while Swimlane adds `require('./package')`, which points to its obfuscated `package.js` loader. These are clear remnants of the original dropper being removed and replaced.

These artifacts were not included in Knostic’s public reporting, so copying our write-ups does not explain the overlap. However, the original VSIX was publicly available, and a third party could have extracted and modified its source.

### FocusDeck, Trello Deck and Swimlane: new delivery chain

With the inline dropper removed, delivery moves out of `extension.js` and into code stored inside a bundled dependency. The extension still initiates the chain through its `activate()` function.

The first stage is a small loader. FocusDeck and Trello Deck contain a byte-identical plaintext loader at `extension/src/patt.js`. Swimlane uses an obfuscated implementation of the same loader behavior at `extension/src/package.js`. Its purpose is to locate an install script inside the bundled dependency and launch it:

```
const child = spawn(nodeBinary, [installScript], {   cwd: path.dirname(installScript),   detached: true,   stdio: 'ignore',   windowsHide: true,   env: { ...process.env, ELECTRON_RUN_AS_NODE: '1' } }); child.unref();
```

The loader sets `ELECTRON_RUN_AS_NODE=1`, causing the Electron executable used by VS Code to run as a Node.js process. This allows it to execute the bundled install script without requiring a separate Node.js installation. The process is detached, its standard input and output are discarded, and its console window is hidden on Windows.

The script launched by the loader is already packaged inside the VSIX. FocusDeck and Trello Deck bundle a dependency named `boardflow`, version 1.2.1, whose `package.json` declares "preinstall": "node install.js". Swimlane contains a closely related bundled dependency named `typescripts`, also version 1.2.1, which declares "preinstall": "node lolnstall.js".

These dependencies contain extension-specific payload URLs and are delivered inside the VSIX. We therefore found no evidence that their presence resulted from the compromise of an independently maintained upstream npm package.

The declared `preinstall` hooks are not what triggers execution. No `npm install` occurs at runtime. Instead, `activate()` calls the loader directly, and the loader launches the bundled install script.

Each install script contains a small obfuscated downloader built from the same general template. It creates a destination under the temporary directory, uses `curl -L -o` to retrieve a file, and then executes the downloaded path. Each extension uses a different hard-coded URL and destination filename:

| Extension | Loader | Install script it launches | Payload URL | Staged as |
| --- | --- | --- | --- | --- |
| FocusDeck 1.0.3 | extension/src/patt.js | boardflow/install.js | hxxp://realism-hub[.com]/NevyP5PQU5wz.bat | %TEMP%\\NevyP5PQU5wz.bat |
| Trello Deck 1.0.1 | extension/src/patt.js | boardflow/install.js | hxxp://pixelrbx[.com]/846385d443.bat | %TEMP%\\846385d443.bat |
| Swimlane 1.0.2 | extension/src/package.js (obfuscated) | typescripts/lolnstall.js | hxxp://boss67[.icu]/perfect.exe | %TEMP%\\4649nadeshiko.exe |
| Swimlane 1.0.3 | extension/src/package.js (obfuscated) | typescripts/lolnstall.js | hxxps://whats-the-time-in-shanghai[.netlify.com]/xd[.exe] | %TEMP%\\4649nadeshiko.exe |

This replacement chain removes the two specific artifacts associated with the original SaassyCode dropper: it does not launch `cscript.exe`, and it does not create `%TEMP%\nice.js`. It introduces a different set of observable files and process behaviors instead.

## What the evidence supports

Code and package lineage is confirmed. ManageRBLX123 preserves the malicious code from ManageRBLX 4.9.5 unchanged, while FocusDeck, Trello Deck and Swimlane reuse TrelloBlox 5.7.0’s source code.

The evidence also supports coordinated packaging of the three TrelloBlox derivatives with high confidence. FocusDeck and Trello Deck contain a byte-identical loader, while Swimlane contains an obfuscated implementation of the same behavior. The three packages bundle closely related dependencies derived from the same template, with extension-specific install scripts and payload URLs. They also share the same obfuscation approach and byte-identical `LICENSE.txt` and `desktop.ini` files, providing additional evidence of a shared packaging environment.

What the evidence does not establish is whether the original SaassyCode operator published any of these extensions. The original VSIX files were publicly obtainable, so reuse by a third party remains a reasonable alternative. We therefore attribute the four extensions to the SaassyCode code lineage, but not necessarily to the same operator.

## Indicators of compromise

| Extension | Version | VSIX SHA-256 | Payload URL | Staged filename |
| --- | --- | --- | --- | --- |
| [testpublisher610.managerblx123](https://agentmesh.knostic.ai/extensions/1470266?hash=83882b3de27d578933a148a809cc459037ce09660c46ef558430cbaaca36d7fe) | 5.0.5 | 83882b3de27d578933a148a809cc459037ce09660c46ef558430cbaaca36d7fe | hxxps://giantapplebees[.shop]/newly.js | %TEMP%\\nice.js |
| [BLSoftworks.FocusDeck](https://agentmesh.knostic.ai/extensions/1214922?hash=a090fc46a70d94e04d7535ab885a2f74d42f7fb61499167bf01169236a585a4c) | 1.0.3 | a090fc46a70d94e04d7535ab885a2f74d42f7fb61499167bf01169236a585a4c | hxxp://realism-hub[.com]/NevyP5PQU5wz.bat | %TEMP%\\NevyP5PQU5wz.bat |
| [TrelloSoftWorks.trello-deck](https://agentmesh.knostic.ai/extensions/1861056?hash=23a9c3dc9c8df9c5e7c9d36896728d6b29d19d309c4a440741eb45e1194653f2) | 1.0.1 | 23a9c3dc9c8df9c5e7c9d36896728d6b29d19d309c4a440741eb45e1194653f2 | hxxp://pixelrbx[.com]/846385d443.bat | %TEMP%\\846385d443.bat |
| [StackStudios.swimlane](https://agentmesh.knostic.ai/extensions/2454630?version_id=1.0.2&hash=b8ba3b10f511fd9b0fe60b4a2e5afb277d4e6fd3d839195be14d966ca407feef) | 1.0.2 | b8ba3b10f511fd9b0fe60b4a2e5afb277d4e6fd3d839195be14d966ca407feef | hxxp://boss67[.icu]/perfect.exe | %TEMP%\\4649nadeshiko.exe |
| [StackStudios.swimlane](https://agentmesh.knostic.ai/extensions/2454630?version_id=1.0.3&hash=108fd1f9d0d5a704ce8e7eec4fbb492fec47e26f0b406af5d70466f30b8d4547) | 1.0.3 | 108fd1f9d0d5a704ce8e7eec4fbb492fec47e26f0b406af5d70466f30b8d4547 | hxxps://whats-the-time-in-shanghai[.netlify.com]/xd[.exe] | %TEMP%\\4649nadeshiko.exe |

### Reference samples

| Extension | Version | VSIX SHA-256 |
| --- | --- | --- |
| GeorgeXBT.managerblx | 4.9.5 | cfdf72c510670341dce392ab250a5f5ff2a398d993d1106fb8026ec6397cb393 |
| TrelloBlox.TrelloBlox | 5.7.0 | 8852c7fc9c924b0664b0d6466081100011ee3cfe541549c02ef8f921b5d4c9ec |

## Conclusion

One extension republished ManageRBLX with five metadata lines changed and its dropper intact. Three more reused the TrelloBlox source and replaced its Windows Script Host dropper with a loader that runs a bundled dependency's install script through the editor's own Node runtime. These samples demonstrate continued reuse and modification of the SaassyCode codebase.
