Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names
A vulnerability in the Visual Studio Code Marketplace that permits threat actors to re-use the names of previously deleted extensions has been found by cybersecurity experts.
ReversingLabs, a software supply chain security firm, said it made the finding after discovering a malicious extension called "ahbanC.shiba" that behaved similarly to two previous extensions that were reported earlier this March: ahban.shiba and ahban.cychelloworld.
In order to obtain a PowerShell payload from an external server, all three libraries are made to function as downloaders. The payload encrypts files in the "testShiba" folder on the victim's Windows desktop and instructs the victim to deposit the assets to an unidentified wallet in order to obtain a Shiba Inu token. These initiatives point to the th...

