Ransomvibe Ransomware Discovered in VS Code Extensions

Ransomvibe Ransomware Discovered in VS Code Extensions

First seen 2 Dec 2025, 18:33 UTC BleepingcomputerCsoonlineDarkreading 84% similarity 30.0

Article Content

Browse articles
ThreatCluster

A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in Visual Studio Code extensions. The malicious extension, named susvsex, was published by an actor identified as 'suspublisher18' and openly advertised its ransomware capabilities. Researcher John Tuckner from Secure Annex highlighted the lack of sophistication in the code, which included obvious signs of being AI-generated.

ThreatCluster AI How this analysis works

Community

Browse all →