ThreatCluster

Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace

First seen 23 Nov 2025, 03:35 UTC Darkreading 60% similarity 31

Article Content

Browse articles
ThreatCluster

A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in extensions on Microsoft's Visual Studio Code marketplace. The malicious extension, named susvsex, was published by an unknown actor and openly advertised its ransomware capabilities, indicating a low level of sophistication. Secure Annex researcher John Tuckner identified the threat, describing it as an example of 'vibe coding'.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story