Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace
Article Content
Browse articles
A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in extensions on Microsoft's Visual Studio Code marketplace. The malicious extension, named susvsex, was published by an unknown actor and openly advertised its ransomware capabilities, indicating a low level of sophistication. Secure Annex researcher John Tuckner identified the threat, describing it as an example of 'vibe coding'.
Ask AI about this cluster
Answers cite the sources they use
Updated 210d ago How this analysis works
More articles in this cluster (1)
Following this threat?
Track Promptlock in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Phishing Threatens School Cybersecurity Schools face increasing risks from AI-driven phishing attacks, including deepfake voice notes and malware like PromptLock that evolves with each execution. With an average of 2,739 edtech tools per district, the reliance on technology makes schools vulnerable to sophisticated scams. Recent surveys indicate that only…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…