Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Socialist Emmanuel Gregoire wins Paris mayoral race | Elections News

    March 23, 2026

    Crimson Desert developer apologizes and promises to replace AI-generated art

    March 23, 2026

    The best Nintendo Switch and Switch 2 accessories for Pokémon superfans

    March 22, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Tech Reviews

    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users

    gvfx00@gmail.comBy gvfx00@gmail.comJanuary 26, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    • Two VSCode extensions exfiltrated sensitive user data to Chinese servers
    • ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined
    • Extensions used hidden iframes, commands, and SDKs to steal files and track activity

    More than 1.5 million people may have had their sensitive data exfiltrated to Chinese hackers through two malicious extensions found on the VSCode Marketplace.

    Security researchers at Koi Security said they discovered two malicious browser extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace, the official Microsoft store for code editor add-ons.

    The extensions were advertised as AI-based coding assistants. Indeed, they worked as advertised, providing users with a simple and convenient way to access a Generative Artificial Intelligence (GenAI) tool to help with coding. However, the tools were also uploading sensitive data to a third-party server in China without telling the users about it.


    You may like

    Table of Contents

    Toggle
    • MaliciousCorgi
      • Related posts:
    • Best Bluetooth Speakers of 2025
    • Intel and AMD trusted enclaves, a foundation for network security, fall to physical attacks
    • OpenAI strikes a deal with the Defense Department to deploy its AI models

    MaliciousCorgi

    According to Koi, these are the add-ons in question, which are both still available for download on the marketplace :

    ChatGPT – 中文版 (publisher: WhenSunset, 1.34 million installs)

    ChatMoss (CodeMoss) (publisher: zhukunpeng, 150k installs)

    Koi says both are part of the ‘MaliciousCorgi’ campaign, and both were sending the stolen data to the same server.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    To exfiltrate the data, they used three distinct mechanisms, it was said. The first one is via real-time monitoring of files opened in VS Code client. As soon as the victim opens a file, its contents are encoded in Base64 and relayed to the servers.

    “The moment you open any file – not interact with it, just open it – the extension reads its entire contents, encodes it as Base64, and sends it to a webview containing a hidden tracking iframe. Not 20 lines. The entire file,” the researchers explained.

    The second mechanism is a server-controlled command that stealthily sends up to 50 files from the victim’s workspace, while the third one is a zero-pixel iframe in the extension’s webview where commercial analytics SDKs are loaded. These SDKs track user behavior, build identity profiles, and monitor other activity.


    You may like

    Microsoft told BleepingComputer it was looking into the situation, but the add-ons are still available for download.

    Via BleepingComputer


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    Related posts:

    Wales vs Belgium live stream: watch FIFA World Cup 2026 qualifier for *FREE*

    The all-electric Jeep Recon gets official specs and launch price

    Today's NYT Mini Crossword Answers for Feb. 7

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleReturn To Silent Hill Sets Franchise-Low US Opening Weekend
    Next Article A Complete Guide to Building Multi-Agent Systems
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Crimson Desert developer apologizes and promises to replace AI-generated art

    March 23, 2026
    Tech Reviews

    La Liga Soccer: Stream Real Madrid vs. Atlético Madrid Live From Anywhere

    March 22, 2026
    Tech Reviews

    I didn’t think the Hyundai Ioniq 5 N could get much better — until I drove its bigger brother

    March 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views

    What is Fine-Tuning? Your Ultimate Guide to Tailoring AI Models in 2025

    October 14, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views

    What is Fine-Tuning? Your Ultimate Guide to Tailoring AI Models in 2025

    October 14, 20259 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.