Hackers Compromising Developers with Malicious VS Code, Cursor AI Extensions
ID: 71c296ca-ddd7-538a-9c78-d57d9e9939e7
STIX ID: report--71c296ca-ddd7-538a-9c78-d57d9e9939e7
Feed Name: cybersecurityNews.com
Threat Score
The report documents research revealing that attackers can publish malicious VS Code and AI-IDE extensions which execute on launch, detect security tools, exfiltrate environment variables containing credentials, and deploy a Merlin command-and-control agent; it also shows sandbox/geo-fencing evasion of Microsoft’s vetting and minimal verification on OpenVSX, creating a significant developer-targeted software supply chain risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
