BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI-Powered Ransomware Found in VS Code Extension, Removed

AI-Generated Malicious VS Code Extension with Ransomware and Vidar-Stealing npm Packages Highlight Growing Supply Chain Attack Risks

  • A malicious Visual Studio Code extension with Ransomware features was released using AI-generated code.
  • The extension encrypts, zips, and uploads files from a test directory and uses GitHub for command-and-control functions.
  • Datadog Security Labs identified 17 npm packages distributing the Vidar information stealer.
  • These npm packages executed Vidar through post-install scripts, using Telegram and Steam accounts as dead drops for command-and-control servers.
  • Supply chain attacks continue to target open-source registries, emphasizing the need for developer caution.

A Visual Studio Code (VS Code) extension named “susvsex” with built-in ransomware capabilities was uploaded on November 5, 2025. The extension, created with apparent assistance from Artificial Intelligence, automatically compresses, uploads, and encrypts files from designated test directories on Windows and macOS systems. John Tuckner, a security researcher at Secure Annex, flagged the extension, which was quickly removed by Microsoft from the official VS Code Marketplace on November 6. More details on the extension can be found in Tuckner’s report and on the marketplace page.

- Advertisement -

The Malware activates upon specific VS Code events, leveraging a function called “zipUploadAndEncrypt” that archives the target directory, uploads it to a remote server, and replaces files with encrypted versions. The current configuration targets a staging directory, limiting immediate damage. The extension communicates with a private GitHub repository using embedded access tokens, polling for commands in an “index.html” file and submitting results to “requirements.txt.” The repository’s owner, linked to the GitHub account “aykhanmv,” reportedly resides in Baku, Azerbaijan.

Meanwhile, Datadog Security Labs uncovered 17 malicious npm packages disguised as benign software development kits that deliver the Vidar info-stealing malware. These packages, uploaded by users “aartje” and “saliii229911,” were first detected on October 21, 2025, and were removed after about 2,240 downloads. The full list of package names is available in their disclosure.

The attack involves a post-install script in the package.json file that downloads a ZIP archive from a domain linked to malicious activity and runs the Vidar executable within it. Some variants use PowerShell commands embedded in the package.json to initiate the download before passing control to JavaScript code. Vidar 2.0 samples utilize hard-coded Telegram and Steam accounts as dead drop points to locate the command-and-control servers.

Security researchers Tesnim Hamdouni, Ian Kretz, and Sebastian Obregoso noted the variation in post-install scripts might help evade detections, as outlined in their analysis. This case adds to a series of supply chain attacks targeting open-source platforms like npm, PyPI, RubyGems, and Open VSX, underscoring the importance of vetting dependencies, reviewing changelogs, and monitoring for typosquatting or dependency confusion prior to installation.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Optimism Rises, but $70K Breakout Stalls

Bitcoin's funding rate climbed to 7%, signaling growing bullish confidence, but persistent spot ETF...

ShapedPlugin WordPress Backdoor in Supply Chain

Pro versions of three ShapedPlugin WordPress extensions were backdoored after attackers hijacked the official...

Saylor’s Strategy Says Its Stock Differs From Terra’s

Analyst Mark Palmer from Benchmark-StoneX rejects comparisons between Strategy’s volatile STRC and the collapsed...

Coinbase Launches AI Pre-IPO Futures for OpenAI & Anthropic

Coinbase has launched pre-IPO perpetual futures for AI giants OpenAI and Anthropic, expanding its...

NY Atty Seeks to Unmask ‘Noah Doe’ Claiming $245B in BTC

An anonymous entity seeks legal title to ~3.8 million dormant BTC, including Satoshi's, valued...

Must Read

This is How to Buy and Sell Bitcoin

Now more than ever, there are a variety of ways to enter and exit the crypto market. While this is good, the availability of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading