DevOps, Supply chain

Nefarious VSCode extensions facilitate infostealer deployment

(Credit: MCGORIE – stock.adobe.com)

BleepingComputer reports that information-stealing malware has been spread through the malicious VSCode extensions Bitcoin Black and Codo AI, both of which were published by 'Big Black' and have since been removed from the marketplace.

Execution of the color theme- and AI assistant-spoofing extensions facilitates the distribution of a Lightshot screenshot tool executable and an illicit DLL file enabling infostealer deployment, which has been undetected by over 40% of antivirus engines on VirusTotal, according to Koi Security researchers.

After creating directories for keeping pilfered data, the malware proceeds to launch Google Chrome and Microsoft Edge in headless mode for cookie exfiltration and user session takeovers, while stealing credentials from Phantom, Exodus, Metamask, and other cryptocurrency wallets.

With malicious VSCode extensions increasingly used to enable malware delivery, as evidenced by the recent Glassworm attack campaign, developers have been urged to ensure that projects they will be using are from trusted publishers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds