VS Code Marketplace Loophole Lets Hackers Reuse Malicious Extension Names

  • Researchers found that removed extension names on the Visual Studio Code Marketplace can be reused by anyone, opening a new attack vector.
  • Malicious extensions have been discovered, including some that demand cryptocurrency for file decryption.
  • The loophole allows threat actors to reuse names previously linked to removed or malicious extensions, posing supply chain risks.
  • Similar vulnerabilities exist in other repositories, such as PyPI, but with additional safeguards not present in Visual Studio Code.
  • Eight dangerous npm packages have been identified, capable of stealing browser data and transmitting it to external servers.

Researchers at ReversingLabs have identified a security loophole within the Visual Studio Code (VS Code) Marketplace that lets anyone reuse the names of previously removed extensions. This means attackers can upload malicious extensions with the same name as those that were previously deleted.

- Advertisement -

According to ReversingLabs, the discovery happened when they spotted a harmful extension named “ahbanC.shiba.” This extension behaves like older ones, such as ahban.shiba and ahban.cychelloworld, which were flagged in March. These extensions download a PowerShell script that targets files in a Windows “testShiba” folder and requests payment in Shiba Inu tokens sent to an unspecified wallet, effectively functioning as Ransomware.

Researchers found that while each extension on the VS Code Marketplace needs a unique combination of publisher and extension names, the platform allows reuse of an extension name once it has been deleted from the repository. Researcher Lucija Valentić explained, “The discovery of this loophole exposes a new threat: that the name of any removed extension can be reused, and by anyone. That means that if some legitimate and very popular extension is removed, its name is up for grabs.”

The same issue has appeared in other open-source repositories like Python’s PyPI, where removed package names can be registered by a new user. However, PyPI has a rule that prevents reusing names associated with previously known malicious packages. The Visual Studio Code documentation doesn’t have such a safeguard, increasing the risk of supply chain attacks.

Attacks involving popular development tools are rising. Recent leaks from Black Basta, a ransomware group, show discussions about using open-source package confusion for ransomware attacks. In addition, JFrog researchers have discovered eight malicious npm packages that can exfiltrate sensitive data like passwords and cryptocurrency information from Chrome browsers to remote servers. These packages include toolkdvv, react-sxt, react-typex, react-typexs, react-sdk-solana, react-native-control, revshare-sdk-api, and revshare-sdk-apii.

- Advertisement -

These npm packages use deeply layered, obfuscated code to hide Python Malware that can steal user information. JFrog researcher Guy Korolevski said, “The impact of sophisticated multi-layer campaigns designed to evade traditional security and steal sensitive data highlights the importance of having visibility across the entire software supply chain with rigorous automated scanning and a single source of truth for all software components.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Waymo’s 2026 Expansion Could Drive Big Gains for GOOGL Surge

Alphabet rallied more than 60% in 2025 and enters 2026 with investor optimism tied...

Tesla shares slip as Q4 deliveries deemed largely neutral US

Tesla delivered 418,227 vehicles in Q4, slightly below the 422,850 company-polled consensus and last...

Institutions Pour In: 2026 Poised to Ignite ETH Value Rise!!

Ethereum insiders say 2026 could trigger significant ETH value growth as institutions increase on-chain...

EU Debates Digital Euro Privacy, Holding Limits: Compromises

The EU Council has endorsed the European Central Bank design for a digital euro...

Iran Military Export Center Accepts Crypto Payments for Arms

Mindex is accepting cryptocurrency for sales of advanced weapons systems.Buyers can pay with crypto,...
- Advertisement -

Must Read

A Beginner’s Guide To Cryptocurrency Mining

Cryptocurrency is considered one of the most popular forms of financial assets today. Many of these digital assets operate within blockchain technology which works...
Bitcoin (BTC) $ 89,670.00 1.85%
Ethereum (ETH) $ 3,108.56 4.12%
XRP (XRP) $ 1.98 5.81%
Bittensor (TAO) $ 244.19 8.12%
Polkadot (DOT) $ 2.05 3.56%
Cardano (ADA) $ 0.381689 8.54%
Chainlink (LINK) $ 13.19 6.13%
Hyperliquid (HYPE) $ 24.59 1.04%
Monero (XMR) $ 420.89 0.15%
Hedera (HBAR) $ 0.118756 5.83%
Toncoin (TON) $ 1.87 10.52%