Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Malicious AI-made extension with ransomware capabilities sneaks on to Microsoft’s official VS Code marketplace – so devs beware

Tech Wavo by Tech Wavo
November 7, 2025
in Computers
0



  • Malicious VS Code extension ‘susvsex’ acted as ransomware and used GitHub for command control
  • Extension appeared AI-generated, with embedded decryption keys and suspicious metadata
  • Microsoft removed it after public pressure, raising concerns about marketplace review gaps

A malicious extension was published on Microsoft’s official VS Code marketplace, and was able to remain there for some time gathering downloads and infecting people’s computers.

Security researcher John Tuckner from Secure Annex found and reported the extension to Microsoft, noting the extension worked as ransomware and to make matters worse, made it “blatantly malicious” by stating, in the description, exactly what it does: “VS Code extension that automatically zips, uploads, and encrypts files from C:\Users\Public\testing on Windows.”

He also explained that the extension, called ‘susvsex’, utilized GitHub as a command-and-control channel and that it was obviously vibe-coded (written with the help of AI and natural language prompts instead of throughlines of code). Some of the evidence of the extension being AI generated included the developer leaving decryption tools and keys in the extension package.


You may like

Vibe coded malware

“Many of these values have comments which indicate that the code was not written directly by the publisher and very likely generated through AI,” Tuckner added.

Since the metadata in the code pointed to a GitHub user in Baku, the researcher speculated that the attacker is located in Azerbaijan. BleepingComputer also argued that the extension, since it was so obviously malicious, could have been just a test of Microsoft’s Visual Studio Marketplace’s review process, in preparation of a more sinister, better obfuscated attack.

Ironically enough, Microsoft at first ignored Tuckner’s report and did not remove it from the VS Code registry. Roughly eight hours after the blog post was published, Tuckner posted a tweet, saying “I tried. No response from ‘Report abuse’ on the marketplace listing yet. Extension is still available.”

However, it seems that Microsoft did respond in the meantime, since the extension’s URL now leads to a “404 – Page not found” site.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Via BleepingComputer


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Previous Post

From Search to Summaries: AI Overview Best Practices for 2025

Next Post

Social Security Employees Grill Management During Tense Shutdown Meeting

Next Post
Social Security Employees Grill Management During Tense Shutdown Meeting

Social Security Employees Grill Management During Tense Shutdown Meeting

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Like Spotify’s new Listening Stats upgrade? Here are 12 other great new features you may have missed this year

by Tech Wavo
November 8, 2025
0
Like Spotify’s new Listening Stats upgrade? Here are 12 other great new features you may have missed this year
Computers

It's been a huge year for Spotify, and now all that's left is the forthcoming arrival of Spotify Wrapped 2025,...

Read more

Your Next Long-Haul Flight Might Be 22 Hours… And Weirdly Comfortable

by Tech Wavo
November 8, 2025
0
Your Next Long-Haul Flight Might Be 22 Hours… And Weirdly Comfortable
Gadgets

Flying from Sydney to London in a single leap has been aviation’s white whale for decades. It’s a route so...

Read more

10 Common Linear Regression Interview Questions + Expert Tips

by Tech Wavo
November 8, 2025
0
10 Common Linear Regression Interview Questions + Expert Tips
News

When it comes to machine learning interviews, Linear Regression almost always shows up. It’s one of those algorithms that looks...

Read more

A portable 4K monitor at a low price sounds great, but having tested it, I can say the QQH Z12-4 isn’t perfect

by Tech Wavo
November 8, 2025
0
A portable 4K monitor at a low price sounds great, but having tested it, I can say the QQH Z12-4 isn’t perfect
Computers

Why you can trust TechRadar We spend hours testing every product or service we review, so you can be sure...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock