logo

Malicious VSCode extensions on Microsoft's registry drop infostealers

ID: c6b6b9f5-cb51-5522-ab90-585e55dd7718

STIX ID: report--c6b6b9f5-cb51-5522-ab90-585e55dd7718

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Two malicious VS Code extensions published as Bitcoin Black and Codo AI (under the developer name 'BigBlack') were found on the Visual Studio Code Marketplace; they used activation events and scripts (PowerShell/batch with curl) to download a legitimate Lightshot executable and a malicious DLL loaded via DLL hijacking to deploy an infostealer named runtime.exe that captures screenshots, credentials, cookies (by launching browsers headlessly), and cryptocurrency wallets, storing data in an '%APPDATA%\Local\Evelyn' directory. Microsoft has since removed the extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.