logo

Taking Down More Malicious VSCode Extensions in the ‘Prettier’ Campaign

ID: 5a85d500-ba34-5c64-b452-a6f5d145dbf7

STIX ID: report--5a85d500-ba34-5c64-b452-a6f5d145dbf7

Feed Name: Checkmarx Zero

Threat Score
50/100

Date Published: 2025-12-05

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

Checkmarx Zero reported a campaign of malicious VSCode extensions that impersonate legitimate packages to gain adoption; attackers used brandjacking and artificially inflated install counts to appear legitimate. Multiple malicious packages targeting known extensions were identified and removed from the VSCode and Open VSX marketplaces with very few downloads, and although these extensions contained no payload at the time of discovery, the actors may push malicious updates later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.