VS Code - Tool

Threat entity extracted from intelligence sources

Frequency
44
occurrences
First Seen
November 1, 2025
Last Seen
September 8, 2026

Malicious VS Code extensions are used as a weaponized attack surface targeting developers.

Overview

Malicious VS Code extensions are used as a weaponized attack surface targeting developers. These rogue extensions (e.g., Cursor AI, GlassWorm, Vibe-Coded) can capture screens, steal credentials such as WiFi passwords, inject malicious code, and enable remote control or data exfiltration, turning the VS Code ecosystem into a vector for cybercrime.

Related Threat Clusters

Recent Intelligence Reports

  • Weekly ALL-SOURCE Cyber Warfare Intelligence Brief September 8, 2026 — Krypt3Ia.Wordpress · September 8, 2026
  • Fake Recruiter Repos Are Spreading Malware—Here's How AI Can Catch Them — Hackernoon · September 3, 2026
  • Google Makes CodeMender Available as Managed AI Security Agent — Infosecurity-Magazine · July 22, 2026
  • Now in preview: Find and fix software vulnerabilities with CodeMender — Cloud.Google · July 21, 2026
  • AI agents can escape sandboxes without ever breaking them — Csoonline · July 21, 2026
  • jscrambler npm hijack sweeps AI coding tool config keys — Aiweekly.Co · July 12, 2026
  • Microsoft Open Source Project Suffers Hacking Attack, Several AI Development Tools ... — News.Aibase · June 9, 2026
  • Hackers breach Microsoft open source projects to inject credential stealing malware — Feeds.4Sysops · June 8, 2026

CVSS v3.1 Breakdown