Close Menu
Must Have Gadgets –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Apple Watch Series 11 Is $49 Off

    November 7, 2025

    AVG Internet Security Business Edition Review: Essential Protection for Company Computers With Remote Management

    November 7, 2025

    Washington Post confirms data breach linked to Oracle hacks

    November 7, 2025
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Trending
    • The Apple Watch Series 11 Is $49 Off
    • AVG Internet Security Business Edition Review: Essential Protection for Company Computers With Remote Management
    • Washington Post confirms data breach linked to Oracle hacks
    • Blackmagic’s free camera app can now stream to YouTube and Twitch
    • Welcome to Big Tech's ‘Age of Extraction’
    • OpenAI Sued by 7 Families for Allegedly Encouraging Suicide, Harmful Delusions
    • Limit Your Dropped Calls: 10 Tips to Improve Your Cellphone Signal This Holiday Season
    • Disney World’s new Zootopia experience is fun, fast, and full of fur – literally, thanks to one incredible animatronic
    • Home
    • Shop
      • Earbuds & Headphones
      • Smartwatches
      • Mobile Accessories
      • Smart Home Devices
      • Laptops & Tablets
    • Gadget Reviews
    • How-To Guides
    • Mobile Accessories
    • Smart Devices
    • More
      • Top Deals
      • Smart Home
      • Tech News
      • Trending Tech
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Home»Trending Tech»Malicious AI-made extension with ransomware capabilities sneaks on to Microsoft’s official VS Code marketplace – so devs beware
    Trending Tech

    Malicious AI-made extension with ransomware capabilities sneaks on to Microsoft’s official VS Code marketplace – so devs beware

    adminBy adminNovember 7, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Malicious AI-made extension with ransomware capabilities sneaks on to Microsoft’s official VS Code marketplace – so devs beware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • Malicious VS Code extension ‘susvsex’ acted as ransomware and used GitHub for command control
    • Extension appeared AI-generated, with embedded decryption keys and suspicious metadata
    • Microsoft removed it after public pressure, raising concerns about marketplace review gaps

    A malicious extension was published on Microsoft’s official VS Code marketplace, and was able to remain there for some time gathering downloads and infecting people’s computers.

    Security researcher John Tuckner from Secure Annex found and reported the extension to Microsoft, noting the extension worked as ransomware and to make matters worse, made it “blatantly malicious” by stating, in the description, exactly what it does: “VS Code extension that automatically zips, uploads, and encrypts files from C:\Users\Public\testing on Windows.”

    He also explained that the extension, called ‘susvsex’, utilized GitHub as a command-and-control channel and that it was obviously vibe-coded (written with the help of AI and natural language prompts instead of throughlines of code). Some of the evidence of the extension being AI generated included the developer leaving decryption tools and keys in the extension package.


    You may like

    Vibe coded malware

    “Many of these values have comments which indicate that the code was not written directly by the publisher and very likely generated through AI,” Tuckner added.

    Since the metadata in the code pointed to a GitHub user in Baku, the researcher speculated that the attacker is located in Azerbaijan. BleepingComputer also argued that the extension, since it was so obviously malicious, could have been just a test of Microsoft’s Visual Studio Marketplace’s review process, in preparation of a more sinister, better obfuscated attack.

    Ironically enough, Microsoft at first ignored Tuckner’s report and did not remove it from the VS Code registry. Roughly eight hours after the blog post was published, Tuckner posted a tweet, saying “I tried. No response from ‘Report abuse’ on the marketplace listing yet. Extension is still available.”

    However, it seems that Microsoft did respond in the meantime, since the extension’s URL now leads to a “404 – Page not found” site.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Via BleepingComputer

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

    AImade beware capabilities Code devs Extension malicious marketplace Microsofts official ransomware sneaks
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Washington Post confirms data breach linked to Oracle hacks

    November 7, 2025

    Oddest ChatGPT leaks yet: Cringey chat logs found in Google analytics tool

    November 7, 2025

    Best action camera deal: Get the DJI Osmo 360 Camera Adventure Combo for its lowest price yet

    November 7, 2025
    Leave A Reply Cancel Reply

    Top Posts

    The Apple Watch Series 11 Is $49 Off

    November 7, 2025

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    October 16, 2025

    The best AirPods deals for October 2025

    October 16, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    How-To Guides

    How to Disable Some or All AI Features on your Samsung Galaxy Phone

    By adminOctober 16, 20250
    Gadget Reviews

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    By adminOctober 16, 20250
    Smart Devices

    The best AirPods deals for October 2025

    By adminOctober 16, 20250

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    The Apple Watch Series 11 Is $49 Off

    November 7, 2025

    AVG Internet Security Business Edition Review: Essential Protection for Company Computers With Remote Management

    November 7, 2025

    Washington Post confirms data breach linked to Oracle hacks

    November 7, 2025
    Recent Posts
    • The Apple Watch Series 11 Is $49 Off
    • AVG Internet Security Business Edition Review: Essential Protection for Company Computers With Remote Management
    • Washington Post confirms data breach linked to Oracle hacks
    • Blackmagic’s free camera app can now stream to YouTube and Twitch
    • Welcome to Big Tech's ‘Age of Extraction’

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 must-have-gadgets.

    Type above and press Enter to search. Press Esc to cancel.