Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Hackers are using malicious Microsoft VSCode extensions to steal passwords

  • May 18, 2023
Total
0
Shares
0
0
0


Cybersecurity researchers from Check Point have discovered multiple malicious Visual Studio extensions sitting in Microsoft’s VSCode Marketplace.

These extensions, called “Theme Darcula dark”, python-vscode”, and “prettiest java” were each pretending to be useful for Visual Studio Code developers, but were, in fact, doing all kinds of nasties. Theme Darcula dark was stealing basic system information, python-vscode allowed for remote code execution on the infected endpoint, while prettiest java stole (impersonating (opens in new tab) the “pretty java” add-on) saved credentials or authentication tokens from Discord and Discord Canary, Google Chrome, Opera, Brave Browser, and Yandex Browser. The malware would later exfiltrate it using a Discord webhook.

Combined, the three malware were downloaded 46,600 times, although, among the three, Theme Darcula dark absolutely dominated with more than 45,000 downloads.

Supply chain attacks

The researchers tipped Microsoft off on May 4 this year, and the company removed them ten days later, on May 14. It’s important to mention while the removal of the malware from the repository does protect developers from future downloads, those that downloaded the malware in the past will remain vulnerable until they remove the tools from their systems and run an antivirus scan to eliminate any remnants. 

Visual Studio Code (VSC) is Microsoft’s source-code editor, used by a “significant percentage” of professional software developers worldwide. VSCode Marketplace is an extensions market run by the Redmond software giant, which allegedly hosts more than 50,000 add-ons that improve VSC’s functionality in various ways. 

While these three were conclusively malicious, Check Point’s researchers found more dubious add-ons which demonstrated some unsafe behavior, but couldn’t outright be classified as malicious. Some of that behavior included grabbing code from private repositories, or downloading files. 

Supply chain attacks are super popular among threat actors these days, and open-source repositories are an attractive target. Other repositories, such as PyPI, for example, are bombarded with malicious packages on a daily basis.

Via: BleepingComputer (opens in new tab)


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

There’s a new bot in town: Tom’s Hardware launches AI-powered chatbot

  • May 18, 2023
View Post
Next Article
  • News

Gears 5 is the first Xbox exclusive to come to GeForce Now as Microsoft cosies up to Nvidia

  • May 18, 2023
View Post
You May Also Like
View Post
  • News

Bryan Fury has been announced for Tekken 8, unannounced and then announced again

  • May 29, 2023
View Post
  • News

Nintendo explains the decision behind blocking release of Dolphin emulator

  • May 29, 2023
View Post
  • News

Microsoft reveals Azure Linux is available now

  • May 29, 2023
View Post
  • News

Nvidia reveals a whole new kind of Ethernet for generative AI

  • May 29, 2023
View Post
  • News

A gaming Chromebook with an Nvidia RTX graphics card? Sign me up

  • May 29, 2023
View Post
  • News

Windows 11 cloud backup is getting a whole lot better at last

  • May 29, 2023
View Post
  • News

HP printers could soon lose their official environmental certification following user fury

  • May 29, 2023
View Post
  • News

Watch out – that Amazon or Microsoft ad could just be malware

  • May 29, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.