logo

AI-Slop ransomware test sneaks on to VS Code marketplace

ID: 04a55709-d161-5d3b-9809-a8ee707f2470

STIX ID: report--04a55709-d161-5d3b-9809-a8ee707f2470

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2025-11-06

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A malicious VS Code extension named 'susvsex' was published on Microsoft's official marketplace and openly advertised file-theft and AES-256-CBC encryption in its description. The extension zips target files, exfiltrates them to a hardcoded C2, replaces files with encrypted versions, and polls a GitHub repo via a hardcoded PAT for commands; researchers characterized it as AI-generated and unsophisticated but potentially dangerous, and reported it to Microsoft who initially did not remove it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.