logo

VS Code Extension Impersonating Zoom Targets Google Chrome Cookies

ID: 83196436-9a66-5033-86d9-3197b56337d4

STIX ID: report--83196436-9a66-5033-86d9-3197b56337d4

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report analyzes a malicious VS Code extension uploaded in late November that impersonated Zoom and was updated to include functionality to access and exfiltrate Google Chrome cookies via a hardcoded endpoint (https://api.storagehb.cn). The authors document the extension's files (dist/extension.js and src/extension-web.js), activation on startup, use of sqlite3 to read the Chrome Cookies SQLite DB, embedded secrets, version history suggesting staged deployment, and provide IOCs (domain, marketplace asset host, VSIX SHA-256) alongside defensive recommendations for vetting extensions and restricting access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.