logo

Malicious Microsoft VSCode extensions target devs, crypto community

ID: be401ce5-d345-5dbe-bd81-a7df7aedd4e0

STIX ID: report--be401ce5-d345-5dbe-bd81-a7df7aedd4e0

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-18

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Researchers discovered a campaign of 18 malicious VSCode extensions (and an associated npm package) that impersonated legitimacy with fake reviews and downloads, then deployed obfuscated downloader code to retrieve AES-encrypted CMD/PowerShell payloads from suspicious domains; secondary payloads were observed on test systems and some dropped binaries were flagged by multiple antivirus engines, with SHA1 indicators published to help detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.