Skip to content
Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace

Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace

First seen 7 Nov 2025, 12:54 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A ransomware-style extension named susvsex, created with basic capabilities and labeled as 'vibe-coded,' was discovered on Microsoft's official VS Code marketplace. The extension, published by 'suspublisher18,' openly advertised its malicious functionality, raising concerns about security in the marketplace. Researcher John Tuckner from Secure Annex identified the extension, noting its lack of sophistication and accidental inclusion of command and control server code.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 205d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Ransomvibe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed