Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Check Your CGM: Recalled FreeStyle Libre 3 Sensors Associated With 7 Deaths

    February 5, 2026

    Overwatch’s Heroes Are Getting Hotter, Here’s Why

    February 4, 2026

    Taylor Sheridan’s TV Shows, Ranked Worst to Best

    February 4, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Tech Reviews

    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users

    gvfx00@gmail.comBy gvfx00@gmail.comJanuary 26, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    • Two VSCode extensions exfiltrated sensitive user data to Chinese servers
    • ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined
    • Extensions used hidden iframes, commands, and SDKs to steal files and track activity

    More than 1.5 million people may have had their sensitive data exfiltrated to Chinese hackers through two malicious extensions found on the VSCode Marketplace.

    Security researchers at Koi Security said they discovered two malicious browser extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace, the official Microsoft store for code editor add-ons.

    The extensions were advertised as AI-based coding assistants. Indeed, they worked as advertised, providing users with a simple and convenient way to access a Generative Artificial Intelligence (GenAI) tool to help with coding. However, the tools were also uploading sensitive data to a third-party server in China without telling the users about it.


    You may like

    Table of Contents

    Toggle
    • MaliciousCorgi
      • Related posts:
    • Compact and comprehensive video production
    • Netflix is reportedly in exclusive talks to acquire Warner Bros. and HBO
    • How OpenAI is using GPT-5 Codex to improve the AI tool itself

    MaliciousCorgi

    According to Koi, these are the add-ons in question, which are both still available for download on the marketplace :

    ChatGPT – 中文版 (publisher: WhenSunset, 1.34 million installs)

    ChatMoss (CodeMoss) (publisher: zhukunpeng, 150k installs)

    Koi says both are part of the ‘MaliciousCorgi’ campaign, and both were sending the stolen data to the same server.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    To exfiltrate the data, they used three distinct mechanisms, it was said. The first one is via real-time monitoring of files opened in VS Code client. As soon as the victim opens a file, its contents are encoded in Base64 and relayed to the servers.

    “The moment you open any file – not interact with it, just open it – the extension reads its entire contents, encodes it as Base64, and sends it to a webview containing a hidden tracking iframe. Not 20 lines. The entire file,” the researchers explained.

    The second mechanism is a server-controlled command that stealthily sends up to 50 files from the victim’s workspace, while the third one is a zero-pixel iframe in the extension’s webview where commercial analytics SDKs are loaded. These SDKs track user behavior, build identity profiles, and monitor other activity.


    You may like

    Microsoft told BleepingComputer it was looking into the situation, but the add-ons are still available for download.

    Via BleepingComputer


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    Related posts:

    The Best Space Heaters in 2025

    These Cyber Monday gaming PC deals are tempting me to upgrade – save thousands on the best towers fr...

    Our favorite 2025 advent calendars from Lego, Pokémon, Funko Pop, Magna-Tiles and more

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleReturn To Silent Hill Sets Franchise-Low US Opening Weekend
    Next Article A Complete Guide to Building Multi-Agent Systems
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Check Your CGM: Recalled FreeStyle Libre 3 Sensors Associated With 7 Deaths

    February 5, 2026
    Tech Reviews

    This Ring Video Doorbell changed how I monitor my home — and 10,000+ people bought it last month

    February 4, 2026
    Tech Reviews

    Broadcom Unveils Comprehensive Enterprise Wi-Fi 8 AP and AI Switch Platforms

    February 4, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views

    What is Fine-Tuning? Your Ultimate Guide to Tailoring AI Models in 2025

    October 14, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views

    What is Fine-Tuning? Your Ultimate Guide to Tailoring AI Models in 2025

    October 14, 20259 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.