HomeSecurityMalicious VSCode extensions infect Windows with cryptominer

Malicious VSCode extensions infect Windows with cryptominer

Nine VSCode extensions in Visual Studio Code pretend to be legitimate development tools, while in fact infecting users with the XMRig cryptominer, for mining Ethereum and Monero.

See also: VSCode extensions downloaded ransomware at an early stage

VSCode cryptominer

Microsoft VSCode is a popular code editor that allows users to install extensions to extend the program's functionality. These extensions can be downloaded from Microsoft's VSCode marketplace, an online platform for developers to search for and install add-ons.

ExtensionTotal researcher Yuval Ronenhas uncovered nine malicious VSCode extensions published on the Microsoft portal on April 4, 2025 that contain cryptominers.

The names of the extensions are:

  • Discord Rich Presence for VS Code (by Mark H) – 189K Installs
  • Rojo – Roblox Studio Sync (by evaera) – 117K Installs
  • Solidity Compiler (by VSCode Developer) – 1.3K Installs
  • Claude AI (by Mark H)
  • Golang Compiler (by Mark H)
  • ChatGPT Agent for VSCode (by Mark H)
  • HTML Obfuscator (by Mark H)
  • Python Obfuscator for VSCode (by Mark H)
  • Rust Compiler for VSCode (by Mark H)

See also: Microsoft apologizes for removing VSCode extensions

The market shows that the extensions have already amassed over 300,000 installs as of April 4. These numbers are likely artificially inflated to give the extensions a sense of legitimacy and popularity, in order to attract more people to install them.

Malicious VSCode extensions infect Windows with cryptominer

ExtensionTotal says it has notified Microsoft of the malicious VSCode extensions containing the cryptominer, but they remain available at this time.

Once installed and activated, the malicious extensions retrieve a PowerShell from an external source at 'https://asdf11[.]xyz/' and execute it. After the process is complete, they also install the legitimate extension they pretend to be, so that the infected user doesn't suspect anything.

The malicious PowerShell script performs several functions, including disabling defense mechanisms, establishing persistence, escalating privileges, and ultimately loading the cryptominer.

If you have installed any of the nine VSCode extensions listed by ExtensionTotal, you should remove them immediately and then manually locate and delete the cryptominer, scheduled tasks, registry key, and malware folder.

See also: Removing popular VSCode extensions for security reasons

Cryptominers , and others. This process is called cryptocurrency mining. Essentially, cryptominers solve complex mathematical problems to verify transactions and add new blocks to the blockchain, which is the distributed database of cryptocurrencies. The process requires a lot of computing power and energy, and for this reason, cryptocurrency mining can be very resource-intensive.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS