top of page
perceptive_background_267k.jpg

Malicious VSCode extensions on Microsoft's registry drop infostealers

Published:

8 December 2025 at 22:30:19

Alert date:

8 December 2025 at 23:00:37

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Two malicious extensions were discovered on Microsoft's Visual Studio Code Marketplace that infect developers' machines with information-stealing malware. The malicious extensions can take screenshots, steal credentials, and hijack browser sessions. This represents a supply chain attack targeting the developer community through compromised extensions in the official Microsoft marketplace. The attack specifically targets developers who are likely to have access to sensitive code repositories and systems. The malware focuses on information theft capabilities including credential harvesting and session hijacking.

Technical details

Mitigation steps:

Affected products:

Visual Studio Code
Microsoft Visual Studio Code Marketplace

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page