Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats

1 min read
Source: The Hacker News
Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats
Photo: The Hacker News
TL;DR Summary

Cybersecurity researchers discovered a vibe-coded malicious VS Code extension with built-in ransomware capabilities, which exfiltrates and encrypts files, and uses GitHub as a command-and-control server. Additionally, 17 npm packages disguised as SDKs were found to stealthily deploy Vidar Stealer, highlighting ongoing supply chain threats in open-source ecosystems. Microsoft has removed the malicious extension from the marketplace, emphasizing the importance of vigilance in software development.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

3 min

vs 4 min read

Condensed

91%

72064 words

Want the full story? Read the original article

Read on The Hacker News