logo

Malicious crypto-stealing VSCode extensions resurface on OpenVSX

ID: e198ec12-e0e3-5c82-9a08-3ee0d6f8d06a

STIX ID: report--e198ec12-e0e3-5c82-9a08-3ee0d6f8d06a

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-14

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

TigerJack, a coordinated multi-account threat actor, is targeting developers with malicious VSCode and OpenVSX extensions that exfiltrate source code, run an unrestricted CoinIMP crypto miner, and poll a hardcoded remote JavaScript to enable arbitrary payload execution; Koi Security observed at least 11 malicious extensions, with two (C++ Playground and HTTP Format) previously reaching ~17,000 downloads on VSCode and still available on OpenVSX, posing significant risk to developer machines and supply-chain integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.