


Perceptive Security
SOC/SIEM Consultancy

Malicious VSCode extensions on Microsoft's registry drop infostealers
Published:
8 december 2025 om 22:30:19
Alert date:
8 december 2025 om 23:00:37
Source:
bleepingcomputer.com
Two malicious extensions were discovered on Microsoft's Visual Studio Code Marketplace that infect developers' machines with information-stealing malware. The malicious extensions can take screenshots, steal credentials, and hijack browser sessions. This represents a supply chain attack targeting the developer community through compromised extensions in the official Microsoft marketplace. The attack specifically targets developers who are likely to have access to sensitive code repositories and systems. The malware focuses on information theft capabilities including credential harvesting and session hijacking.
Technical details
Mitigation steps:
Affected products:
Visual Studio Code
Microsoft Visual Studio Code Marketplace
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
