Two malicious Microsoft Visual Studio Code (VS Code) extensions have been found by cybersecurity experts. These extensions are marketed as AI-powered coding aids, but they also have hidden features that allow developer data to be siphoned to servers located in China.
The extensions can still be downloaded from the official Visual Studio Marketplace and have a cumulative install count of 1.5 million. They are mentioned below:
- ChatGPT – 中文版 (ID: whensunset.chatgpt-china) – 1,340,869 installs
- ChatGPT – ChatMoss(CodeMoss)(ID: zhukunpeng.chat-moss) – 151,751 installs
According to Koi Security, the extensions are functional and perform as intended, but they also record all file openings and source code modifications to servers in China without the users’ knowledge or agreement. MaliciousCorgi is the code name for the campaign.
According to security expert Tuval Admoni, both have the same malicious code—the same spyware infrastructure read more about Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
