ThreatCluster

Malicious VS Code Extensions Exploit Microsoft Registry to Steal WiFi Passwords

First seen 9 Dec 2025, 14:54 UTC CyberpressGbhackersCybersecuritynews 42

Article Content

Browse articles
ThreatCluster

A series of malicious Visual Studio Code extensions have been identified, exploiting vulnerabilities in the Microsoft Registry to steal WiFi passwords and capture screens. Users of Windows systems are particularly affected due to weak registry and process controls that allow these extensions to operate undetected.