Malicious VSCode extensions with millions of installs discovered
ID: 36d141a0-0200-5d76-b35a-cae9ddbc84f0
STIX ID: report--36d141a0-0200-5d76-b35a-cae9ddbc84f0
Feed Name: Bleeping Computer
Researchers demonstrated a supply-chain style attack on the Visual Studio Code Marketplace by publishing a typosquatted 'Darcula' theme that included code to collect host and environment data and exfiltrate it to a remote server. Their broader analysis using a tool called 'ExtensionTotal' found thousands of extensions with malicious or risky behaviors (reverse shells, hardcoded IPs, unknown executables, publisher impersonation), many with millions of installs, and highlighted weak marketplace controls and EDR blind spots that allow wide-scale abuse of VSCode extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
