Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats

1 min read
Source: The Hacker News
Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats
Photo: The Hacker News
TL;DR

Cybersecurity researchers discovered a vibe-coded malicious VS Code extension with built-in ransomware capabilities, which exfiltrates and encrypts files, and uses GitHub as a command-and-control server. Additionally, 17 npm packages disguised as SDKs were found to stealthily deploy Vidar Stealer, highlighting ongoing supply chain threats in open-source ecosystems. Microsoft has removed the malicious extension from the marketplace, emphasizing the importance of vigilance in software development.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News