VS Code - Tool

Threat entity extracted from intelligence sources

Frequency
42
occurrences
First Seen
November 1, 2025
Last Seen
July 22, 2026

VS Code is a tool tracked across 34 threat clusters and 42 intelligence report mentions on ThreatCluster. First observed November 1, 2025; most recent activity July 22, 2026.

Overview

Malicious VS Code extensions are used as a weaponized attack surface targeting developers. These rogue extensions (e.g., Cursor AI, GlassWorm, Vibe-Coded) can capture screens, steal credentials such as WiFi passwords, inject malicious code, and enable remote control or data exfiltration, turning the VS Code ecosystem into a vector for cybercrime.

Related Threat Clusters

Recent Intelligence Reports

  • Google Makes CodeMender Available as Managed AI Security Agent — Infosecurity-Magazine · July 22, 2026
  • Now in preview: Find and fix software vulnerabilities with CodeMender — Cloud.Google · July 21, 2026
  • AI agents can escape sandboxes without ever breaking them — Csoonline · July 21, 2026
  • jscrambler npm hijack sweeps AI coding tool config keys — Aiweekly.Co · July 12, 2026
  • Microsoft Open Source Project Suffers Hacking Attack, Several AI Development Tools ... — News.Aibase · June 9, 2026
  • Hackers breach Microsoft open source projects to inject credential stealing malware — Feeds.4Sysops · June 8, 2026
  • Microsoft’s open source tools were hacked to steal passwords of AI developers — Techcrunch · June 8, 2026
  • Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency — Proofpoint · June 8, 2026

CVSS v3.1 Breakdown