Bleepingcomputer Malicious VS Code Extensions Distribute Infostealers to Developers
Article Content
Browse articles
Two malicious Visual Studio Code extensions, Bitcoin Black and Codo AI, were found on the VS Code marketplace, capable of stealing screenshots, browser sessions, and stored credentials. The extensions were reported by Koi Security and utilized social engineering tactics to deliver a DLL-based infostealer to developers' machines.
Ask AI about this cluster
Answers cite the sources they use
Updated 196d ago How this analysis works
More articles in this cluster (6)
Following this threat?
Track Glassworm and OpenVSX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PEEP Chrome Extension Turns Browsers Into Remote Access Tools Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be installed, allowing it to bypass Web Store checks and inject itself directly into Chrome and Edge profiles.…