Bleepingcomputer
Ransomvibe Ransomware Discovered in VS Code Extensions
First seen 2 Dec 2025, 18:33 UTC
•

•84% similarity
•30.0
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in Visual Studio Code extensions. The malicious extension, named susvsex, was published by an actor identified as 'suspublisher18' and openly advertised its ransomware capabilities. Researcher John Tuckner from Secure Annex highlighted the lack of sophistication in the code, which included obvious signs of being AI-generated.
ThreatCluster AI
How this analysis works