Malicious Visual Studio Code extensions target developers with hidden malware

techradar.com

Researchers have identified over a dozen malicious Visual Studio Code extensions targeting software developers, particularly in web3 and cryptocurrency. These extensions deploy hidden second-stage malware from suspicious domains, complicating detection. The campaign, first reported in early October 2024, includes heavily obfuscated files that download additional malware. The malicious packages are designed for popular tools like Zoom and Solidity, with similar threats found on NPM. The number of affected systems is likely in the thousands, making the attack hard to detect. Developers are advised to verify software packages carefully before downloading.


With a significance score of 4.4, this news ranks in the top 3% of today's 28695 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Malicious Visual Studio Code extensions target developers with hidden malware | News Minimalist