Skip to content
Ransomvibe Ransomware Discovered in VS Code Extensions

Ransomvibe Ransomware Discovered in VS Code Extensions

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in Visual Studio Code extensions. The malicious extension, named susvsex, was published by an actor identified as 'suspublisher18' and openly advertised its ransomware capabilities. Researcher John Tuckner from Secure Annex highlighted the lack of sophistication in the code, which included obvious signs of being AI-generated.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 205d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track Promptlock and Ransomvibe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed