Malicious AI extensions on VSCode Marketplace steal developer data
ID: 51428bca-ef1e-5abe-977f-1f67b4b0a4e2
STIX ID: report--51428bca-ef1e-5abe-977f-1f67b4b0a4e2
Feed Name: Bleeping Computer
Threat Score
Researchers found two malicious Visual Studio Code extensions (collectively installed ~1.5M times) that silently exfiltrate opened files, can be commanded to harvest up to 50 workspace files, and load analytics SDKs for device/user profiling; the campaign (MaliciousCorgi) sends Base64-encoded source files and potentially sensitive configuration/credential data to China-based backend servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
