Threats Tagged 'vs code'
View all threats tagged with 'vs code'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vs code'
Click on any threat for detailed analysis and mitigation recommendations
The Contagious Interview campaign, attributed to North Korea, continues to target software developers through fake recruitment schemes. A new technique in their arsenal leverages Microsoft Visual Studio Code task files to execute malicious code when a project is opened. The report documents observations of this vector, presents GitHub-based discovery methods, highlights findings including a new malicious NPM package, and outlines detection opportunities. The campaign exploits VS Code's Task feature, using the runOptions property to automatically execute malicious shell commands when a workspace is opened. Various obfuscation techniques are employed, including hiding commands with whitespace and masquerading payloads as image or font files. Join the discussion | AlienVault OTX General | 01/23/2026, 10:13:28 UTC Added: 01/23/2026, 10:50:56 UTC |
A malicious campaign has compromised 19 Visual Studio Code extensions by embedding malware within dependency folders, specifically by modifying the legitimate npm package 'path-is-absolute'. Active since February 2025, the attackers disguise malicious binaries as PNG images within archives to evade detection. When VS Code starts, a JavaScript dropper decodes and executes two malicious binaries using living-off-the-land binaries, enabling stealthy execution. This attack leverages trusted components from the VS Code Marketplace, complicating detection and mitigation. Although no known exploits in the wild have been reported, the campaign demonstrates advanced evasion techniques and targets a widely used development environment. The malware involves a Rust-based trojan and employs multiple tactics such as code obfuscation, masquerading files, and abuse of legitimate binaries. European organizations using VS Code with affected extensions are at risk of compromise, data theft, or further lateral movement. Mitigation requires careful vetting of extensions, monitoring for suspicious activity, and restricting execution of untrusted binaries. Countries with strong software development sectors and high VS Code adoption are most likely to be impacted. Given the stealth, potential for privilege escalation, and broad impact, the threat severity is assessed as high. Join the discussion | AlienVault OTX General | 12/11/2025, 12:06:21 UTC Added: 12/11/2025, 14:54:37 UTC |
A loophole in VS Code Marketplace allows malicious actors to reuse names of removed extensions. ReversingLabs discovered this vulnerability after finding a malicious extension with the same name as one previously identified. The platform's documentation states that extension names must be unique, but removed extensions' names can be reused. This poses a risk of threat actors publishing malicious extensions under previously legitimate names. The research team conducted experiments to confirm this vulnerability, successfully publishing extensions with names of removed packages. This technique has been observed in other open-source platforms like PyPI. The discovery highlights the increasing popularity of VS Code Marketplace among malicious actors and the need for developers to be vigilant about package security. Join the discussion | AlienVault OTX General | 08/29/2025, 01:02:09 UTC Added: 08/29/2025, 09:02:49 UTC |
A VS Code extension for Ethereum smart contract development, ETHcode, was compromised through a GitHub pull request. The attacker, using a newly created account, submitted a PR that introduced a malicious dependency and code to execute it. The compromise was subtle, involving only two lines of code changes among thousands. The malicious code downloads and runs a batch script from a public file-hosting service, potentially to steal crypto assets or compromise Ethereum contracts. The extension, with nearly 6,000 installs, was removed from the marketplace after discovery. This incident highlights the importance of carefully reviewing contributions, especially from new accounts, and scrutinizing package dependencies in software development workflows. Join the discussion | AlienVault OTX General | 07/09/2025, 13:49:14 UTC Added: 07/09/2025, 19:39:57 UTC |
Showing 1 to 4 of 4 results