Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace
First seen 23 Nov 2025, 03:35 UTC
•
•60% similarity
•31
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
Browse articles
A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in extensions on Microsoft's Visual Studio Code marketplace. The malicious extension, named susvsex, was published by an unknown actor and openly advertised its ransomware capabilities, indicating a low level of sophistication. Secure Annex researcher John Tuckner identified the threat, describing it as an example of 'vibe coding'.
ThreatCluster AI
How this analysis works