HomeSecurityVS Code: Malicious AI extensions steal developer data

VS Code: Malicious AI extensions steal developer data

Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions, advertised as AI-powered coding assistants, but containing hidden functionality to data developer and send it to servers based in China.

See also: Stanley malware toolkit sends you to phishing site while URL remains the same

VS Code Malicious AI Extensions

The extensions, which have a total of 1.5 million installations and are still available for download from the official Visual Studio Marketplace, are:

– ChatGPT – Chinese version (ID: whensunset.chatgpt-china) – 1,340,869 installations

– ChatGPT – ChatMoss(CodeMoss) (ID: zhukunpeng.chat-moss) – 151,751 installations

Koi Security reported that the extensions are functional and work as expected, but they record every file opened and every code modification on servers located in China, without the knowledge or consent of users. The campaign has been codenamed MaliciousCorgi.

VS Code: Malicious AI extensions steal developer data

“Both contain identical malicious code — the same spyware infrastructure operating under different publisher names,” said security researcher Tuval Admoni.

See also: Konni hackers use AI-generated PowerShell backdoor

What makes the activity particularly dangerous is that the extensions work exactly as advertised, providing autocomplete suggestions and explaining coding errors, thus avoiding the appearance of red flags and reducing user suspicions.

How malicious code works in VS Code extensions

The embedded malicious code is designed to read the entire contents of each file that is opened, encode in Base64 format, and send it to a server located in China (“aihao123[.]cn”). This process is triggered for every edit.

See also: New sneaky phishing campaign targets Marriott & Microsoft customers

VS Code: Malicious AI extensions steal developer data

The extensions also incorporate a monitoring feature real-time that can be triggered remotely from the server, causing up to 50 files to be exported to the workspace. In addition, a hidden zero-pixel iframe loads four commercial analytics software development kits (SDKs) for device identification and building extended user profiles.

The four SDKs used are Zhuge.io, GrowingIO, TalkingData and Baidu Analytics, large analytics platforms based in China.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS