Skip to content
ThreatCluster

Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace

First seen 23 Nov 2025, 03:35 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in extensions on Microsoft's Visual Studio Code marketplace. The malicious extension, named susvsex, was published by an unknown actor and openly advertised its ransomware capabilities, indicating a low level of sophistication. Secure Annex researcher John Tuckner identified the threat, describing it as an example of 'vibe coding'.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

More articles in this cluster (1)

Following this threat?

Track Promptlock in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed