logo

Malicious VS Code Extensions Deploy Advanced Infostealer

ID: 001f8ba6-1cba-5445-95e0-2bc35efd123e

STIX ID: report--001f8ba6-1cba-5445-95e0-2bc35efd123e

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-22

...
...

Koi Security identified two malicious VS Code extensions (Bitcoin Black and Codo AI) distributed via the VS Code marketplace that used social engineering and DLL hijacking (pairing a legitimate Lightshot executable with a malicious DLL) to deliver an infostealer capable of exfiltrating screenshots, browser sessions, stored credentials, WiFi passwords, clipboard data and other system information; Microsoft removed the referenced extensions after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.