Cybersecurity researchers have discovered two new extensions in the Microsoft Visual Studio Code (VS Code) Marketplace, which are designed to infect developers' machines with data-stealing malware.
See also: Malicious VS Code add-on targets Windows and macOS users

The VS Code extensions pretend to be a premium dark theme and an artificial intelligence (AI) coding assistant, but in reality they contain hidden functions to download additional payloads, take screenshots, and scrape data. The collected information is sent to a server controlled by the attackers.
“Your password. Your emails. Your Slack messages. Whatever is on your screen, they see it,” said Idan Dardikman of Koi Security. “And that’s just the beginning. It also steals your WiFi passwords, reads your clipboard, and hijacks your browser sessions.”
Microsoft has removed the following extensions from the Marketplace:
– BigBlack.bitcoin-black (16 installations) – Removed on December 5, 2025
– BigBlack.codo-ai (25 installations) – Removed on December 8, 2025
Microsoft’s list of removed extensions also includes a third package named “BigBlack.mrbigblacktheme” from the same publisher due to malware content. While “BigBlack.bitcoin-black” is triggered on every VS Code action, Codo AI embeds its malicious functionality within a workflow tool, allowing it to bypass detection.
See also: Glassworm malware: New malicious VS Code packages

Previous versions of the extensions could run a PowerShell script to download a password-protected ZIP file from an external server and extract the main payload using various methods. However, the attacker accidentally distributed a version that created a visible PowerShell window, which could alert the user. Subsequent versions hid the window and simplified the process by using a batch script with the curl command to download the executable and DLL.
The executable is the legitimate Lightshot binary used to load the malicious DLL (“Lightshot.dll”) via DLL hijacking, which collects clipboard contents, list of installed applications, running processes, desktop snapshots, saved Wi-Fi credentials, and detailed system information. It also launches Google Chrome and Microsoft Edge, to grab saved cookies and hijack user sessions.
The revelation comes as Socket identified malicious packages in the Go, npm, and Rust ecosystems capable of collecting sensitive data.
Go packages named “github.com/bpoorman/uuid” and “github.com/bpoorman/uid” have been available since 2021 and spoof trusted UUID libraries to output data to a paste site when an application calls a supposed helper function named “valid.”
A set of 420 unique npm packages published by a potential French-speaking attacker follow a consistent naming pattern that includes “elf-stats-*“, some of which contain code to execute a reverse shell and export files to a Pipedream endpoint.
See also: New 'SleepyDuck' malware on Open VSX allows remote control of Windows

A Rust crate named finch-rust, published by faceless, impersonates the legitimate bioinformatics tool “finch” and acts as a loader for a malicious payload via a credential stealing package known as “sha-rust” when a developer uses the library’s sketch serialization functionality.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
