Developers have had their data exfiltrated to China-based servers by a pair of illicit Microsoft Visual Studio Code extensions purporting to be AI-based coding assistants as part of the MaliciousCorgi campaign, BleepingComputer reports.Both ChatGPT and ChatMoss (CodeMoss) apps, which have been cumulatively downloaded over 1.5 million times, had identical spyware infrastructure and obtained data using three different techniques, according to Koi Security researchers. Aside from performing real-time transmission of files opened in VS Code, the extensions also use a server-controlled file-harvesting command that allows the covert transmission of up to 50 files, as well as a zero-pixel iframe that loads four different commercial analytics to monitor user activity, said researchers, who emphasized the potential exposure of source code, cloud service credentials, and configuration files due to the extensions.Microsoft, which has yet to remove the extensions from the VS Code Marketplace, has already launched an investigation into Koi's findings.
AI/ML, Supply chain, Data Security
Developer data theft sought by nefarious AI extensions on VS Code
(Credit: MCGORIE – stock.adobe.com)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
