Tech

Developers targeted by malicious Microsoft VSCode extensions

Share
Share


  • Reversing Labs and Assaraf discover campaign targeting software and web3 devs
  • Multiple packages were hiding weaponized code that deploys stage-two malware
  • The malicious intent was very difficult to spot

Software developers, especially those working on web3 and cryptocurrency projects, are being targeted in a brand new software supply chain attack, experts have claimed.

Security researcher Amit Assaraf published a new blog post outlining how he had observed dozens of malicious Visual Studio Code extensions on the VSCode marketplace designed to download well-hidden second-stage payloads from shady domains (some in Russia).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
AI took a huge leap in IQ, and now a quarter of Gen Z thinks AI is conscious
Tech

AI took a huge leap in IQ, and now a quarter of Gen Z thinks AI is conscious

ChatGPT’s o3 model scored a 136 on the Mensa IQ test and...

DeepSeek sees surge in developer use as 3 in 10 businesses adopt the controversial LLM provider
Tech

DeepSeek sees surge in developer use as 3 in 10 businesses adopt the controversial LLM provider

Developers shift from loyalty to flexibility as OpenAI leads, but DeepSeek gains...

China’s CATL launches new EV sodium battery
Tech

China’s CATL launches new EV sodium battery

Chinese battery giant CATL has launched a new sodium-ion battery it says...