logo

Malicious VS Code on Microsoft Registry Captures Your Screen and Steals Your WiFi Passwords

ID: 3f1403d8-c79b-5c28-af35-ac5704793353

STIX ID: report--3f1403d8-c79b-5c28-af35-ac5704793353

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious campaign distributed via two Visual Studio Code Marketplace extensions (Bitcoin Black and Codo AI) from the same publisher 'BigBlack' installs an infostealer that captures desktop screenshots, harvests clipboard contents, enumerates running processes, exfiltrates stored WiFi credentials, and hijacks browser sessions by launching Chrome/Edge in headless mode to steal session cookies; the malware achieves persistence and evasion through DLL hijacking of a signed Lightshot binary and signals presence with a mutex named COOL_SCREENSHOT_MUTEX_YARRR, while researchers observed the actor streamlining delivery (moving from passworded ZIPs to direct downloads using native tools like curl).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.