Cybersecurity researchers have discovered a new threat targeting developers using Visual Studio Code (VS Code).
See also: New Glove infostealer bypasses Chrome cookie encryption

A malicious extension disguised as a Zoom app has been discovered stealing cookies from Google Chrome, raising concerns about the security of the VS Code extension ecosystem.
The deceptive extension, uploaded to the VS Code Marketplace on November 30, 2024 and last updated on December 8, impersonates the Zoom Workspace. To bolster its credibility, the uploader included a link to the legitimate GitHub repository for the Zoom Meeting SDK.
The core functionality of the malicious extension is contained in two main files:-
- ./dist/extension.js: Responsible for enabling and disabling the extension.
- ./src/extension-web.js: Contains the main logic of the extension.
See also: Hackers breach email accounts with MFA by stealing cookies
Researchers at Hunt.io discovered that the extension is triggered using the “onStartupFinished” event in the package.json, ensuring that any malicious code is executed once VS Code is fully loaded.

An SQL query is used to extract sensitive information from Chrome's cookie database:-
SELECT host_key, name, encrypted_value, path, expires_utc, is_secure, is_httponly, creation_utc, has_expires, is_persistent FROM cookie
This query retrieves various cookie attributes, including encrypted values, expiration dates, and security flags.
The VS Code extension was initially released as versions 0.2.0 and 0.2.1 on November 30, with the code targeting Google Chrome introduced in version 0.2.2 on December 8. This suggests a deliberate strategy to bypass early detection mechanisms.
See also: Hackers steal cookies to gain access to your accounts
Cookie theft is a malicious practice often used by attackers to gain access to sensitive user data. Using techniques such ascross-site scripting(XSS), attackers can steal cookies, which contain login information or session data. This allows the attacker to impersonate the user, gaining unauthorized access to accounts and services. Protecting against these types of attacks requires adopting good security practices, such as proper data validation and using secure connections.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
