Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Star Fox Is Back, So What's Nintendo's Excuse For Other Abandoned Franchises?

    May 7, 2026

    How Does the ‘Duck Dynasty’ Family Compound Work?

    May 7, 2026

    Rivian R2: More Versions Coming?

    May 7, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Tech Reviews

    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users

    gvfx00@gmail.comBy gvfx00@gmail.comJanuary 26, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    • Two VSCode extensions exfiltrated sensitive user data to Chinese servers
    • ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined
    • Extensions used hidden iframes, commands, and SDKs to steal files and track activity

    More than 1.5 million people may have had their sensitive data exfiltrated to Chinese hackers through two malicious extensions found on the VSCode Marketplace.

    Security researchers at Koi Security said they discovered two malicious browser extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace, the official Microsoft store for code editor add-ons.

    The extensions were advertised as AI-based coding assistants. Indeed, they worked as advertised, providing users with a simple and convenient way to access a Generative Artificial Intelligence (GenAI) tool to help with coding. However, the tools were also uploading sensitive data to a third-party server in China without telling the users about it.


    You may like

    Table of Contents

    Toggle
    • MaliciousCorgi
      • Related posts:
    • NordVPN lets you block adult sites from loading, but only on mobile
    • Windows 10 support has ended, but here's how to get an extra year for free
    • Best Earbuds and Headphones for Workouts and the Gym in 2025

    MaliciousCorgi

    According to Koi, these are the add-ons in question, which are both still available for download on the marketplace :

    ChatGPT – 中文版 (publisher: WhenSunset, 1.34 million installs)

    ChatMoss (CodeMoss) (publisher: zhukunpeng, 150k installs)

    Koi says both are part of the ‘MaliciousCorgi’ campaign, and both were sending the stolen data to the same server.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    To exfiltrate the data, they used three distinct mechanisms, it was said. The first one is via real-time monitoring of files opened in VS Code client. As soon as the victim opens a file, its contents are encoded in Base64 and relayed to the servers.

    “The moment you open any file – not interact with it, just open it – the extension reads its entire contents, encodes it as Base64, and sends it to a webview containing a hidden tracking iframe. Not 20 lines. The entire file,” the researchers explained.

    The second mechanism is a server-controlled command that stealthily sends up to 50 files from the victim’s workspace, while the third one is a zero-pixel iframe in the extension’s webview where commercial analytics SDKs are loaded. These SDKs track user behavior, build identity profiles, and monitor other activity.


    You may like

    Microsoft told BleepingComputer it was looking into the situation, but the add-ons are still available for download.

    Via BleepingComputer


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    Related posts:

    Lenovo Yoga Pro 9i 16 Aura Edition Review: Kick-Ass Laptop for Creators

    How Wi-Fi Works vs. False Marketing 101: Real-World Tips

    US bans new foreign-made drones and components

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleReturn To Silent Hill Sets Franchise-Low US Opening Weekend
    Next Article A Complete Guide to Building Multi-Agent Systems
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    I’m a password expert – and these are my top five tips for picking the right password manager

    May 7, 2026
    Tech Reviews

    Synology BC510 and TC510: No More Built-In Camera License

    May 7, 2026
    Tech Reviews

    Ars Asks: Share your shell and show us your tricked-out terminals!

    May 7, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025140 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202572 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 202570 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025140 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202572 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 202570 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.