AI-Slop ransomware test sneaks on to VS Code marketplace
ID: 04a55709-d161-5d3b-9809-a8ee707f2470
STIX ID: report--04a55709-d161-5d3b-9809-a8ee707f2470
Feed Name: Bleeping Computer
A malicious VS Code extension named 'susvsex' was published on Microsoft's official marketplace and openly advertised file-theft and AES-256-CBC encryption in its description. The extension zips target files, exfiltrates them to a hardcoded C2, replaces files with encrypted versions, and polls a GitHub repo via a hardcoded PAT for commands; researchers characterized it as AI-generated and unsophisticated but potentially dangerous, and reported it to Microsoft who initially did not remove it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
