BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious VS Code Extensions Steal Developer Data, Removed by Microsoft

Malicious Developer Tools and Packages Target Microsoft VS Code and Popular Programming Ecosystems with Advanced Data-Stealing Malware

  • Malicious extensions disguised as developer tools were found in the Microsoft Visual Studio Code Marketplace.
  • The extensions stole sensitive data such as WiFi passwords, clipboard contents, screenshots, and browser sessions.
  • Malware used advanced techniques like DLL hijacking and headless browser sessions to extract information.
  • Microsoft removed several infected extensions from its Marketplace promptly after detection.
  • Additional malicious packages were discovered in the Go, npm, and Rust ecosystems targeting developers.

Cybersecurity researchers uncovered two malicious extensions in the Microsoft Visual Studio Code (VS Code) Marketplace that infected developer machines with stealer malware. These extensions appeared as a premium dark theme and an Artificial Intelligence coding assistant but secretly downloaded further payloads, captured screenshots, and siphoned sensitive data. The stolen information was transmitted to a server controlled by attackers.

- Advertisement -

The infected extensions—named BigBlack.Bitcoin-black with 16 installs and BigBlack.codo-ai with 25 installs—were removed by Microsoft in early December 2025. A third related package, BigBlack.mrbigblacktheme, was also removed for containing malware according to Microsoft’s list of removed Marketplace extensions. As stated by Idan Dardikman from Koi Security, “Your code. Your emails. Your Slack DMs. Whatever’s on your screen, they’re seeing it too.” The malware additionally compromised WiFi credentials, clipboard data, and hijacked browser sessions.

Initial versions executed PowerShell scripts to download a password-protected ZIP archive from an external source (syn1112223334445556667778889990[.]org), extracting the main payload using methods like Windows native tools and 7-Zip. Later versions concealed these activities by hiding the PowerShell window and switched to batch scripts that utilized curl to download an executable and DLL.

The malware loaded a genuine Lightshot screen capture binary that then loaded a malicious “Lightshot.dll” via DLL hijacking. This DLL collected clipboard contents, lists of installed applications and processes, desktop screenshots, saved WiFi credentials, and detailed system information. It also launched Google Chrome and Microsoft Edge browsers in headless mode to extract stored cookies and hijack user sessions, as described here.

Separately, the firm Socket identified malicious packages targeting popular programming ecosystems: two Go packages impersonating trusted UUID libraries that exfiltrate data to a paste site called dpaste when specific functions are invoked; over 400 npm packages bearing the prefix “elf-stats-,” with some enabling reverse shells and data exfiltration; and a Rust crate named finch-rust that masquerades as a legitimate bioinformatics tool while loading a credential-stealing payload called sha-rust. Socket researcher Kush Pandya explained, “Finch-rust acts as a malware loader… finch-rust looks benign in isolation, while sha-rust contains the actual malware.” More details on these threats are available through Socket’s reports, npm findings, and Rust crate analysis.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Micron Stock $5k by 2030? Forecasts Show Likely Shortfall

Transforming a $500 investment in Micron stock into $5,000 by 2030 would require a...

Candidate sells 10 Bitcoin for $800K to fund campaign

Republican candidate Michael Carbonara sold 10 Bitcoin for $800,000 in USDC to self-fund his...

ARK Buys HOOD, Trims During Rally, Adds Defense Stock

Ark Invest sold $13.6 million worth of Robinhood (HOOD) shares on Friday, profit-taking as...

SHIB: How a $13 Investment Could Have Made Millions

Shiba Inu (SHIB) price remains down approximately 94% from its 2021 all-time high of...

U.S. seizes $1B in Iranian crypto assets in economic crackdown

The U.S. Treasury has seized roughly $1 billion in Iranian cryptocurrency assets, doubling a...

Must Read

10 Best Crypto to Mine Without Special Hardware Equipment

A lot of people mostly think that it takes a difficult process to mine cryptocurrency. today we are going to show you some of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading