Bleepingcomputer
Malicious VS Code Extensions Distribute Infostealers to Developers
First seen 9 Dec 2025, 17:52 UTC
•


•77% similarity
•50.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Two malicious Visual Studio Code extensions, Bitcoin Black and Codo AI, were found on the VS Code marketplace, capable of stealing screenshots, browser sessions, and stored credentials. The extensions were reported by Koi Security and utilized social engineering tactics to deliver a DLL-based infostealer to developers' machines.
ThreatCluster AI
How this analysis works