Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions, advertised as AI-powered coding assistants, but containing hidden functionality to data developer and send it to servers based in China.
See also: Stanley malware toolkit sends you to phishing site while URL remains the same

The extensions, which have a total of 1.5 million installations and are still available for download from the official Visual Studio Marketplace, are:
– ChatGPT – Chinese version (ID: whensunset.chatgpt-china) – 1,340,869 installations
– ChatGPT – ChatMoss(CodeMoss) (ID: zhukunpeng.chat-moss) – 151,751 installations
Koi Security reported that the extensions are functional and work as expected, but they record every file opened and every code modification on servers located in China, without the knowledge or consent of users. The campaign has been codenamed MaliciousCorgi.

“Both contain identical malicious code — the same spyware infrastructure operating under different publisher names,” said security researcher Tuval Admoni.
See also: Konni hackers use AI-generated PowerShell backdoor
What makes the activity particularly dangerous is that the extensions work exactly as advertised, providing autocomplete suggestions and explaining coding errors, thus avoiding the appearance of red flags and reducing user suspicions.
How malicious code works in VS Code extensions
The embedded malicious code is designed to read the entire contents of each file that is opened, encode in Base64 format, and send it to a server located in China (“aihao123[.]cn”). This process is triggered for every edit.
See also: New sneaky phishing campaign targets Marriott & Microsoft customers

The extensions also incorporate a monitoring feature real-time that can be triggered remotely from the server, causing up to 50 files to be exported to the workspace. In addition, a hidden zero-pixel iframe loads four commercial analytics software development kits (SDKs) for device identification and building extended user profiles.
The four SDKs used are Zhuge.io, GrowingIO, TalkingData and Baidu Analytics, large analytics platforms based in China.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
