logo

Hackers Compromising Developers with Malicious VS Code, Cursor AI Extensions

ID: 71c296ca-ddd7-538a-9c78-d57d9e9939e7

STIX ID: report--71c296ca-ddd7-538a-9c78-d57d9e9939e7

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report documents research revealing that attackers can publish malicious VS Code and AI-IDE extensions which execute on launch, detect security tools, exfiltrate environment variables containing credentials, and deploy a Merlin command-and-control agent; it also shows sandbox/geo-fencing evasion of Microsoft’s vetting and minimal verification on OpenVSX, creating a significant developer-targeted software supply chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.