Incident Score: Analysis & Impact (AMACLONPM1786444537)
The details regarding individual company incidents & reports gives you full view from every side.
Rankiteo Score Impact Analysis
Key Highlights From The Incident Analysis
- Timeline of Amazon Science's Cyber Attack and lateral movement inside company's environment.
- Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
- How Rankiteo’s incident engine converts technical details into a normalized incident score.
- How this cyber incident impacts Amazon Science Rankiteo cyber scoring and cyber rating.
- Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.
Full Incident Analysis Transcript
In this Rankiteo incident briefing, we review the Amazon Science breach identified under incident ID AMACLONPM1786444537.
The analysis begins with a detailed overview of Amazon Science's information like the linkedin page: https://www.linkedin.com/company/amazonscience, the number of followers: 386739, the industry type: Research Services and the number of employees: 4 employees
After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 750 and after the incident was 732 with a difference of -18 which is could be a good indicator of the severity and impact of the incident.
In the next step of the video, we will analyze in more details the incident and the impact it had on Amazon Science and their customers.
Solidity and Ethereum Developers recently reported "Malicious VS Code Extensions Target Solidity and Ethereum Developers with Credential Theft", a noteworthy cybersecurity incident.
Security firm Yeeth Security uncovered a campaign involving malicious Visual Studio Code (VS Code) extensions, disguised as 'Solidity Pro', designed to steal sensitive credentials from Solidity and Ethereum developers.
The disruption is felt across the environment, affecting Developer machines, VS Code and its forks (Cursor, Windsurf, Codium, Positron), and exposing GitHub tokens, cloud credentials, wallet seeds, SSH keys, URL credentials, 1Password MFA tokens.
In response, moved swiftly to contain the threat with measures like Extensions removed from Open VSX.
The case underscores how Ongoing, teams are taking away lessons such as Need for provenance checks, allow-list management, and behavioral monitoring in extension supply chains. Marketplace moderation alone is insufficient to prevent delayed-activation threats, and recommending next steps like Implement provenance checks for VS Code extensions, Use allow-list management for extensions and Enhance behavioral monitoring for delayed-activation threats.
Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.
The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.
MITRE ATT&CK® Correlation Analysis
Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Supply Chain Compromise: Compromise Software Supply Chain (T1195.002) with high confidence (90%), with evidence including malicious VS Code Extensions disguised as Solidity Pro, and npm package `ascii-fetcher` with malicious dependency and User Execution: Malicious File (T1204.002) with moderate to high confidence (80%), supported by evidence indicating developers installed malicious VS Code extensions and npm packages. Under the Execution tactic, the analysis identified Command and Scripting Interpreter: JavaScript (T1059.007) with moderate to high confidence (80%), supported by evidence indicating extensions executed JavaScript payloads, HTA droppers, Command and Scripting Interpreter: Windows Command Shell (T1059.003) with moderate to high confidence (70%), supported by evidence indicating npm package used `child_process.exec` with `windowsHide` for silent execution, and Container Administration Command (T1609) with moderate confidence (60%), supported by evidence indicating extensions targeted VS Code forks (Cursor, Windsurf, Codium, Positron). Under the Persistence tactic, the analysis identified Browser Extensions (T1176) with high confidence (90%), supported by evidence indicating malicious VS Code extensions installed and persisted on developer machines and Compromise Client Software Binary (T1554) with moderate to high confidence (80%), supported by evidence indicating extensions disguised as legitimate Solidity Pro tools. Under the Privilege Escalation tactic, the analysis identified Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002) with moderate confidence (50%), supported by evidence indicating extensions may have leveraged developer privileges for credential access. Under the Defense Evasion tactic, the analysis identified Obfuscated Files or Information (T1027) with high confidence (90%), supported by evidence indicating heavy obfuscation, splitting strings across IIFEs, reassembling at runtime, Virtualization/Sandbox Evasion: Time Based Evasion (T1497.003) with moderate to high confidence (80%), supported by evidence indicating delayed activation hours/days after installation to evade sandboxing, and Masquerading: Match Legitimate Name or Location (T1036.005) with high confidence (90%), supported by evidence indicating extensions disguised as Solidity Pro, clean intermediate versions published. Under the Credential Access tactic, the analysis identified Unsecured Credentials: Credentials In Files (T1552.001) with high confidence (90%), supported by evidence indicating harvested GitHub tokens, AWS keys, Cloudflare tokens, SSH keys, wallet seeds, Unsecured Credentials: Private Keys (T1552.004) with high confidence (90%), supported by evidence indicating sSH private keys, Bitcoin WIF/xprv keys, wallet vaults (MetaMask, Phantom), Credentials from Password Stores: Credentials from Web Browsers (T1555.003) with moderate to high confidence (70%), supported by evidence indicating uRL credentials and 1Password MFA tokens stolen, and Multi-Factor Authentication Interception (T1111) with moderate confidence (60%), supported by evidence indicating 1Password MFA tokens harvested. Under the Collection tactic, the analysis identified Data from Local System (T1005) with high confidence (90%), supported by evidence indicating collected source control tokens, cloud credentials, wallet data, SSH keys and Clipboard Data (T1115) with moderate to high confidence (80%), supported by evidence indicating clipboard stealer swapped cryptocurrency addresses via `vscode.env.clipboard.writeText`. Under the Command and Control tactic, the analysis identified Web Service: Bidirectional Communication (T1102.002) with moderate to high confidence (80%), supported by evidence indicating exfiltrated data via Telegram bot, fetched payloads from Cloudflare Workers and Application Layer Protocol: Web Protocols (T1071.001) with moderate to high confidence (70%), supported by evidence indicating used Cloudflare Workers for encrypted Python payload delivery. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with high confidence (90%), supported by evidence indicating stolen data exfiltrated via Telegram bot and Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) with moderate confidence (60%), supported by evidence indicating potential use of Cloudflare Workers for data staging. Under the Impact tactic, the analysis identified Resource Hijacking (T1496) with moderate to high confidence (70%), supported by evidence indicating cryptocurrency address swapping via clipboard stealer and Account Access Removal (T1531) with moderate confidence (50%), supported by evidence indicating potential unauthorized access to repositories/cloud infrastructure. These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.
Sources & References
- Amazon Science Rankiteo Cyber Incident Details: https://www.rankiteo.com/company/amazonscience/incident/AMACLONPM1786444537
- Amazon Science CyberSecurity Rating page: https://www.rankiteo.com/company/amazonscience
- Amazon Science Rankiteo Cyber Incident Blog Article: https://blog.rankiteo.com/amaclonpm1786444537-cloudflare-amazon-web-services-npm-cyber-attack-may-2025/
- Amazon Science CyberSecurity Score History: https://www.rankiteo.com/company/amazonscience/history
- Amazon Science CyberSecurity Incident Source: https://dailysecurityreview.com/cyber-security/solidity-pro-vs-code-extensions-steal-wallets-api-keys-from-devs/
- Rankiteo A.I CyberSecurity Rating methodology: https://www.rankiteo.com/Images/rankiteo_algo.pdf
- Rankiteo TPRM Scoring methodology: https://static.rankiteo.com/model/rankiteo_tprm_methodology.pdf