HomeSecurityMalicious VS Code imitates Zoom app and steals Chrome cookies

Malicious VS Code mimics Zoom app and steals Chrome cookies

Cybersecurity researchers have discovered a new threat targeting developers using Visual Studio Code (VS Code).

See also: New Glove infostealer bypasses Chrome cookie encryption

VS Code cookies

A malicious extension disguised as a Zoom app has been discovered stealing cookies from Google Chrome, raising concerns about the security of the VS Code extension ecosystem.

The deceptive extension, uploaded to the VS Code Marketplace on November 30, 2024 and last updated on December 8, impersonates the Zoom Workspace. To bolster its credibility, the uploader included a link to the legitimate GitHub repository for the Zoom Meeting SDK.

The core functionality of the malicious extension is contained in two main files:-

  1. ./dist/extension.js: Responsible for enabling and disabling the extension.
  2. ./src/extension-web.js: Contains the main logic of the extension.

See also: Hackers breach email accounts with MFA by stealing cookies

Researchers at Hunt.io discovered that the extension is triggered using the “onStartupFinished” event in the package.json, ensuring that any malicious code is executed once VS Code is fully loaded.

Malicious VS Code mimics Zoom app and steals Chrome cookies

An SQL query is used to extract sensitive information from Chrome's cookie database:-

SELECT host_key, name, encrypted_value, path, expires_utc, is_secure, is_httponly, creation_utc, has_expires, is_persistent FROM cookie

This query retrieves various cookie attributes, including encrypted values, expiration dates, and security flags.

The VS Code extension was initially released as versions 0.2.0 and 0.2.1 on November 30, with the code targeting Google Chrome introduced in version 0.2.2 on December 8. This suggests a deliberate strategy to bypass early detection mechanisms.

See also: Hackers steal cookies to gain access to your accounts

Cookie theft is a malicious practice often used by attackers to gain access to sensitive user data. Using techniques such ascross-site scripting(XSS), attackers can steal cookies, which contain login information or session data. This allows the attacker to impersonate the user, gaining unauthorized access to accounts and services. Protecting against these types of attacks requires adopting good security practices, such as proper data validation and using secure connections.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS