logo

Loophole allows threat actors to claim VS Code extension names

ID: 40a7447f-7fa6-551d-9383-25890258d407

STIX ID: report--40a7447f-7fa6-551d-9383-25890258d407

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2025-08-28

Date Updated: 2026-04-29

Author: Lucija Valentić

...
...

ReversingLabs researchers discovered a VS Code Marketplace loophole where names of removed extensions can be reused by any publisher; malicious actors exploited this to publish downloader extensions (e.g., ahban.shiba, ahbanC.shiba) that retrieve a second-stage PowerShell payload from 54.85.145.93 which performs file encryption and demands payment in Shiba Inu tokens. The report documents the timeline, reproduction experiments showing removed names are re-publishable, and provides IOCs and mitigation recommendations, warning of broader supply-chain risks for developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.