cognitive cybersecurity intelligence

News and Analysis

Search

Data-stealing VS Code extensions removed from official Marketplace

Data-stealing VS Code extensions removed from official Marketplace

Malicious VS Code extensions aimed at developers writing Ethereum smart contracts have been identified as installing malware that pilfers cryptocurrency wallet credentials. The attack is connected to threat actor MUT-9332, which recently distributed a Monero cryptominer. The malicious extensions configure to launch with VS Code, initiating a multistage infection chain that installs credential-stealing extensions on Chromium-based browsers. The malware also creates a firewall rule to block Microsoft updates and telemetry infrastructure. Users have been advised to vet extensions before use.

Source: www.helpnetsecurity.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts