Tech

Developers targeted by malicious Microsoft VSCode extensions

Share
Share


  • Reversing Labs and Assaraf discover campaign targeting software and web3 devs
  • Multiple packages were hiding weaponized code that deploys stage-two malware
  • The malicious intent was very difficult to spot

Software developers, especially those working on web3 and cryptocurrency projects, are being targeted in a brand new software supply chain attack, experts have claimed.

Security researcher Amit Assaraf published a new blog post outlining how he had observed dozens of malicious Visual Studio Code extensions on the VSCode marketplace designed to download well-hidden second-stage payloads from shady domains (some in Russia).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
When the school bell rings, the bandwidth drops: How post-15:40 internet surges affect UK broadband quality
Tech

When the school bell rings, the bandwidth drops: How post-15:40 internet surges affect UK broadband quality

Half of parents work after school, causing a broadband battle with streaming-addicted...

You can put Google Gemini right on your smartphone home screen – here’s how
Tech

You can put Google Gemini right on your smartphone home screen – here’s how

Google has launched Gemini home screen widgets for Android and iOS devices...

You can now fact check anybody’s post in WhatsApp – here’s how
Tech

You can now fact check anybody’s post in WhatsApp – here’s how

Perplexity AI’s new WhatsApp integration offers instant fact-checking without leaving the app...