“This stage involves downloading and executing a ScreenConnect installer, which is typically known as a legitimate remote desktop application.”

truffelvscode typosquats a real VS Code extension on npm. Three stages later, the machine runs ScreenConnect pointed at the attacker. The final payload is legitimate remote desktop software, so defenders see nothing unusual.