Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Puragen unveils PFAS treatment technology during UK ministerial visit

Compromised dYdX npm and PyPI packages deliver wallet stealer and RAT malware

DiDAX: Innovating DNA-based data applications

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Researchers discover malicious VS Code, Go, npm, and Rust packages that steal developer data
Identity

Researchers discover malicious VS Code, Go, npm, and Rust packages that steal developer data

userBy userDecember 9, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 9, 2025Ravi LakshmananMalware/Threat Analysis

Cybersecurity researchers have discovered two new extensions in the Microsoft Visual Studio Code (VS Code) Marketplace that are designed to infect developers’ machines with stealer malware.

The VS Code extension pretends to be a coding assistant powered by a premium dark theme and artificial intelligence (AI), but it actually hides secret features that allow it to download additional payloads, take screenshots, and siphon data. The captured information is sent to an attacker-controlled server.

“Your code, your email, your Slack DMs. Whatever you’re seeing on your screen, they’re seeing it too,” said Idan Dardikman of Koi Security. “And that’s just the beginning. They also steal WiFi passwords, read clipboards, and hijack browser sessions.”

cyber security

The names of the extensions are as follows –

BigBlack.bitcoin-black (16 installations) – Removed by Microsoft on December 5, 2025 BigBlack.codo-ai (25 installations) – Removed by Microsoft on December 8, 2025

A list of extensions that Microsoft has removed from its marketplace shows that the company also removed a third package from the same publisher named “BigBlack.mrbigblacktheme” for containing malware.

“BigBlack.bitcoin-black” is activated with every VS Code action, but Codo AI embeds its malicious functionality within the tools it runs, allowing it to evade detection.

Previous versions of the extension included the ability to run a PowerShell script to download a password-protected ZIP archive from an external server (“syn1112223334445556667778889990[.]org”) and extracts the main payload using four different methods: Windows native Expand-Archive, .NET System.IO.Compression, DotNetZip, and 7-Zip (if installed).

However, the attackers are said to have inadvertently shipped a version that could create a visible PowerShell window and alert users. However, in subsequent iterations, I found that switching to a batch script that uses the curl command to download executables and DLLs hides the window and streamlines the entire process.

This executable is a legitimate Lightshot binary that is used to load a malicious DLL (‘Lightshot.dll’) via DLL hijacking, which collects clipboard contents, list of installed apps, running processes, desktop screenshots, saved Wi-Fi credentials, and detailed system information. It also launches Google Chrome and Microsoft Edge in headless mode to retrieve stored cookies and hijack user sessions.

“When a developer installs what appears to be a benign theme or useful AI tool, WiFi passwords, clipboard contents, and browser sessions can be exposed to a remote server within seconds,” Durdikman said.

cyber security

This disclosure comes after Socket announced that it had identified malicious packages capable of collecting sensitive data across the Go, npm, and Rust ecosystems.

A Go package named “github”[.]com/bpoorman/uuid” and “github”[.]com/bpoorman/uid” and typosquat’s trusted UUID library (“github[.]com/google/uuid” and “github”[.]com/pborman/uuid”) to extract the data to a paste site called dpaste when the application explicitly calls the expected helper function named “valid” with the information to be validated. A set of 420 unique npm packages, likely published by a French-speaking attacker, that follow a consistent naming pattern that includes “elf-stats-*”. Part of it includes code that runs a reverse shell and extracts files into Pipedream. A Rust crate named finch-rust published by faceless. It impersonates the legitimate bioinformatics tool ‘finch’ and acts as a loader for malicious payloads via a credential-stealing package known as ‘sha-rust’ when developers use the library’s sketch serialization functionality.

“Finch-rust acts as a malware loader. It contains most of the legitimate code copied from the legitimate finch package, but one malicious line that loads and executes the sha-rust payload,” said socket researcher Kush Pandya. “This separation of concerns makes it difficult to detect. While finch-rust appears harmless on its own, sha-rust contains actual malware.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFTC upholds ban on stalkerware founder Scott Zuckerman
Next Article AI-powered full material declarations crack the PFAS code
user
  • Website

Related Posts

Compromised dYdX npm and PyPI packages deliver wallet stealer and RAT malware

February 6, 2026

Claude Opus 4.6 discovers over 500 high-severity flaws across major open source libraries

February 6, 2026

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

February 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Puragen unveils PFAS treatment technology during UK ministerial visit

Compromised dYdX npm and PyPI packages deliver wallet stealer and RAT malware

DiDAX: Innovating DNA-based data applications

Claude Opus 4.6 discovers over 500 high-severity flaws across major open source libraries

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.