Cybercriminals are beginning to target the Microsoft VSCode Marketplace, having uploaded three malicious extensions of Visual Studio, which Windows developers have downloaded 46,600 times.

See also: ScanSource announced it had fallen victim to a ransomware attack
According to Check Point, whose analysts discovered the malicious extensions and reported them to Microsoft, the malware allowed threat actors to steal credentials, system information , and create a remote shell on the victim's machine.
The extensions were discovered and reported on May 4, 2021 and were subsequently removed from the VSCode marketplace on May 14, 2021.
However, those software developers who still use the malicious extensions should manually remove them from their systems and run a full scan to detect any remnants of the infection.
See also: Ransomware group asks for charity donation instead of ransom
Malicious cases in the VSCode Marketplace
Visual Studio Code (VSC) is a source code editor published by Microsoft and used by a significant percentage of professional software developers worldwide.
Microsoft also operates an extension marketplace for the IDE called VSCode Marketplace, which offers over 50,000 extensions that extend the application's functionality and provide more customization options.
The malicious extensions discovered by Check Point researchers are as follows:
'Theme Darcula dark' – “Described as “an attempt to improve the consistency of Dracula colors in VS Code”, this extension was used to steal basic information about the developer's system, including hostname, operating system, CPU platform, total memory , and CPU information”
Although the extension did not contain any other malicious activity, it is not typical behavior associated with a theme package.
This extension has long had the highest circulation, as it was downloaded over 45,000 times.

'python-vscode' – This extension was downloaded 1,384 times despite its empty description and uploader name “testUseracc1111”, showing that a good name is enough to garner some interest.
Its code analysis showed that it is a C# shell injector, which can execute code or commands on the victim’s computer.

'prettiest java' – Based on the extension's name and description, it was likely created to emulate the popular code formatting tool “Prettier-Java”.
In reality, it stole stored credentials or authentication tokens from Discord and Discord Canary, Google Chrome, Opera, Brave Browser and Yandex Browser, which were then sent to the attackers via a Discord webhook.
The extension had 278 installations.

Check Point also detected many suspicious extensions, which could not be definitively classified as malicious, however they exhibited unsafe behavior, such as retrieving code from private repositories or downloading files.
See also: Cisco: Warns of critical switch flaws with public exploit code

Software repositories are at risk
Software repositories that allow user contributions, such as NPM and PyPI, have repeatedly proven to be dangerous to use, as they have become popular targets for threat actors.
While the VSCode Marketplace has only just started to become a target, AquaSec demonstrated in January that it was fairly easy to upload malicious extensions to the VSCode Marketplace and presented several highly suspicious cases, however it could not find any malware.
The cases discovered by Check Point demonstrate that threat actors are now actively trying to infect Windows developers with malicious submissions, just as they do on other software repositories, such as NPM and PyPI .
Users of the VSCode Marketplace and all user-supported repositories are advised to install extensions only from trusted publishers with many downloads and community ratings, read user reviews, and always check the source code of the extension before installing it.
Information source: bleepingcomputer.com
