Skip to content
Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Order Of The Sinking Star’s Biggest Villain Is Its Own Creator

    June 22, 2026

    ‘Toy Story 5’ Had 2026’s Biggest Opening Weekend

    June 22, 2026

    Did Chevrolet just tease the next Camaro? NASCAR show car sparks speculation

    June 22, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
    Tech Reviews

    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users

    gvfx00@gmail.comBy gvfx00@gmail.comJanuary 26, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    • Two VSCode extensions exfiltrated sensitive user data to Chinese servers
    • ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined
    • Extensions used hidden iframes, commands, and SDKs to steal files and track activity

    More than 1.5 million people may have had their sensitive data exfiltrated to Chinese hackers through two malicious extensions found on the VSCode Marketplace.

    Security researchers at Koi Security said they discovered two malicious browser extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace, the official Microsoft store for code editor add-ons.

    The extensions were advertised as AI-based coding assistants. Indeed, they worked as advertised, providing users with a simple and convenient way to access a Generative Artificial Intelligence (GenAI) tool to help with coding. However, the tools were also uploading sensitive data to a third-party server in China without telling the users about it.


    You may like

    Table of Contents

    Toggle
    • MaliciousCorgi
      • Related posts:
    • Regular vs. Smart Thermostats: Everything You Wanted to Know
    • YouTube TV vs. Hulu Plus Live TV: Which Offers the Best Experience for Your Buck?
    • A single click mounted a covert, multistage attack against Copilot

    MaliciousCorgi

    According to Koi, these are the add-ons in question, which are both still available for download on the marketplace :

    ChatGPT – 中文版 (publisher: WhenSunset, 1.34 million installs)

    ChatMoss (CodeMoss) (publisher: zhukunpeng, 150k installs)

    Koi says both are part of the ‘MaliciousCorgi’ campaign, and both were sending the stolen data to the same server.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    To exfiltrate the data, they used three distinct mechanisms, it was said. The first one is via real-time monitoring of files opened in VS Code client. As soon as the victim opens a file, its contents are encoded in Base64 and relayed to the servers.

    “The moment you open any file – not interact with it, just open it – the extension reads its entire contents, encodes it as Base64, and sends it to a webview containing a hidden tracking iframe. Not 20 lines. The entire file,” the researchers explained.

    The second mechanism is a server-controlled command that stealthily sends up to 50 files from the victim’s workspace, while the third one is a zero-pixel iframe in the extension’s webview where commercial analytics SDKs are loaded. These SDKs track user behavior, build identity profiles, and monitor other activity.


    You may like

    Microsoft told BleepingComputer it was looking into the situation, but the add-ons are still available for download.

    Via BleepingComputer


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    Related posts:

    Crucial Pro OC DDR5-6400: Solid Overclocking RAM

    Steam store pages get a mini makeover to better suit wide screens

    Canon unveils a Limited Edition version of its popular G7 X III compact camera

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleReturn To Silent Hill Sets Franchise-Low US Opening Weekend
    Next Article A Complete Guide to Building Multi-Agent Systems
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Today’s NYT Strands Hints, Answer and Help for June 22 #841- CNET

    June 21, 2026
    Tech Reviews

    How to watch Belgium vs Iran: Free Streams & TV Channels for World Cup 2026

    June 21, 2026
    Tech Reviews

    Before SpaceX IPO, investors in China secretly acquired stakes

    June 21, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025204 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025129 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202599 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025204 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025129 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202599 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.