Malicious VS Code extensions are used as a weaponized attack surface targeting developers.
Overview
Malicious VS Code extensions are used as a weaponized attack surface targeting developers. These rogue extensions (e.g., Cursor AI, GlassWorm, Vibe-Coded) can capture screens, steal credentials such as WiFi passwords, inject malicious code, and enable remote control or data exfiltration, turning the VS Code ecosystem into a vector for cybercrime.
Related Threat Clusters
-
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
22 articles · Updated August 30, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026 -
Jscrambler npm Package Compromised in Supply Chain Attack
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
18 articles · Updated July 12, 2026 -
Supply Chain Attack Targets Checkmarx KICS Tool via Docker and VSCode Extensions
Hackers have compromised Docker images and VSCode extensions for the Checkmarx KICS analysis tool, which is used to identify security vulnerabilities in source code. The attack involved a trojanized KICS Docker image…
2 articles · Updated April 23, 2026 -
GlassWorm Malware Campaign Targets OpenVSX with 73 Malicious Extensions
A resurgence of the GlassWorm malware campaign has been identified, targeting the OpenVSX ecosystem with 73 'sleeper' extensions that become malicious after updates. Six of these extensions have already been activated…
8 articles · Updated April 27, 2026 -
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
30 articles · Updated May 27, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
Critical Vulnerability in MCP Protocol Exposes 200,000 AI Servers to Remote Code Execution
A report by OX Security has identified a critical vulnerability in the Model Context Protocol (MCP) developed by Anthropic, potentially exposing over 200,000 AI servers to remote code execution. The flaw lies in the…
12 articles · Updated April 16, 2026 -
TeamPCP Targets CI/CD Pipelines to Steal Developer Credentials
TeamPCP, a financially motivated threat actor, has been conducting a campaign targeting software supply chains from March 19 to April 24, 2026. The group exploited trusted CI/CD and release workflows to steal sensitive…
4 articles · Updated May 15, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026
Recent Intelligence Reports
- Weekly ALL-SOURCE Cyber Warfare Intelligence Brief September 8, 2026 — Krypt3Ia.Wordpress · September 8, 2026
- Fake Recruiter Repos Are Spreading Malware—Here's How AI Can Catch Them — Hackernoon · September 3, 2026
- Google Makes CodeMender Available as Managed AI Security Agent — Infosecurity-Magazine · July 22, 2026
- Now in preview: Find and fix software vulnerabilities with CodeMender — Cloud.Google · July 21, 2026
- AI agents can escape sandboxes without ever breaking them — Csoonline · July 21, 2026
- jscrambler npm hijack sweeps AI coding tool config keys — Aiweekly.Co · July 12, 2026
- Microsoft Open Source Project Suffers Hacking Attack, Several AI Development Tools ... — News.Aibase · June 9, 2026
- Hackers breach Microsoft open source projects to inject credential stealing malware — Feeds.4Sysops · June 8, 2026