Two malicious VSCode Marketplace extensions were detected downloading ransomware at an early stage, revealing serious weaknesses in Microsoft.
See also: Microsoft apologizes for removing VSCode extensions

The extensions, named “ahban.shiba” and “ahban.cychelloworld,” were downloaded seven and eight times respectively before they were finally removed from the store.
It is noteworthy that the extensions were posted to the VSCode Marketplace on October 27, 2024 (ahban.cychelloworld) and February 17, 2025 (ahban.shiba), bypassing security review processes and remaining in the Microsoft store for an extended period of time.
VSCode Marketplace is an online platform where developers can search, install, and share extensions for Visual Studio Code (VSCode). It is widely used by developers , data scientists, and programmers.
ReversingLabs discovered that the two extensions contain a PowerShell that downloads and executes another PS script, which acts as ransomware, from a remote server hosted on Amazon AWS. The ransomware downloaded by the VSCode extensions is clearly under development or testing, as it only encrypts files in the C:\users\%username%\Desktop\testShiba and does not touch any other files.
See also: Removing popular VSCode extensions for security reasons
After the file encryption is complete, the script will display a Windows notification stating: “Your files have been encrypted. Pay 1 ShibaCoin to ShibaWallet to recover them.” No ransom notes or additional instructions are provided as is usually the case in ransomware attacks.

ReversingLabs reports that Microsoft immediately removed the two extensions from the VSCode Marketplace after the researchers reported them.
However, ExtensionTotal security researcher Italy Kruksaid that their automated scanner detected the extensions earlier and informed Microsoft some time ago, without receiving any response.
Kruk explains that ahban.cychelloworld was not malicious when it was initially posted. The ransomware code was added to its second submission, version 0.0.2 , which was accepted into the VSCode Marketplace on November 24, 2024. Since then, the ahban.cychelloworld extension has had five more versions, all of which contained the malicious code , and all of which were accepted into the Microsoft store
The finding that the extensions downloaded and executed remote PowerShell scripts, remaining invisible for nearly four months, points to a worrying weakness in Microsoft's vetting process.
See also: Malicious VSCode extensions target crypto developers and investors
Early -stage ransomware refers to the initial phase or process of a ransomware attack, where malicious code begins to enter a network or system and prepares the ground for the attack. In this phase, cybercriminals may do the following:
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Target identification and identification: Detecting weaknesses and vulnerabilities in the system or network that can be exploited.
- Initial intrusion: They use malware to enter the computer or network, without yet performing the actual encryption of the data.
- Environment recognition: Attackers may collect information about the data structure and control the system before taking action.
Source: bleepingcomputer
