At least 11 malicious VSCode extensions have been uploaded by the threat actor TigerJack to facilitate cryptocurrency theft and backdoor injections against developers since the beginning of this year, with the C++ Playground and HTTP Format extensions reappearing in the OpenVSX registry after being removed from VSCode, BleepingComputer reports.Execution of C++ Playground enables source code exfiltration to various endpoints, while HTTP Format facilitates clandestine CoinIMP miner deployment, according to a Koi Security report. Meanwhile, more nefarious TigerJack extensions allowed JavaScript code retrieval and execution."TigerJack can dynamically push any malicious payload without updating the extensionstealing credentials and API keys, deploying ransomware, using compromised developer machines as entry points into corporate networks, injecting backdoors into your projects, or monitoring your activity in real-time," said Koi Security researchers.OpenVSX has already been informed regarding the malicious extensions but has yet to respond.
Application security, DevOps

Illicit VSCode extensions seek to pilfer cryptocurrency

(Credit: Postmodern Studio – stock.adobe.com)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



