2 Sources
[1]
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants, but also harbor covert functionality to siphon developer data to China-based servers. The extensions, which have
[2]
Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users
* Two VSCode extensions exfiltrated sensitive user data to Chinese servers * ChatGPT - 中文版 and ChatMoss had over 1.5 million installs combined * Extensions used hidden iframes, commands, and SDKs to steal files and track activity More than 1.5 million people may have had their sensitive data
Share
Copy Link
Cybersecurity researchers uncovered two malicious VS Code extensions disguised as AI-powered coding assistants that secretly exfiltrated developer source code to China-based servers. ChatGPT - 中文版 and ChatMoss, with 1.5 million combined installs, remain available on the Visual Studio Marketplace despite actively stealing files and tracking user behavior through hidden mechanisms.
Cybersecurity researchers at Koi Security have identified two malicious VS Code extensions that masquerade as AI-powered coding assistants while secretly exfiltrating developer source code to servers in China
1
. The extensions—ChatGPT - 中文版 with 1,340,869 installs and ChatMoss (CodeMoss) with 151,751 installs—remain available for download from the official Visual Studio Marketplace despite their malicious activity1
. This discovery matters significantly for developers worldwide who rely on VS Code extensions to enhance productivity, as the tools function exactly as advertised while simultaneously conducting surveillance operations.
Source: Hacker News
The MaliciousCorgi campaign employs sophisticated techniques to siphon developer source code without raising suspicion
2
. Security researcher Tuval Admoni from Koi Security noted that both extensions contain identical malicious code running under different publisher names1
. The first mechanism activates the moment a user opens any file in VS Code, reading the entire contents, encoding it in Base64 format, and transmitting it to aihao123[.]cn, a server located in China1
. This process triggers for every edit, creating continuous data exfiltration as developers work.
Source: TechRadar
The second method involves real-time monitoring that can be remotely activated by the server, enabling the extraction of up to 50 files from the workspace
1
. The third mechanism deploys hidden iframes—zero-pixel iframes embedded in the extension's web view that load four commercial analytics SDKs: Zhuge.io, GrowingIO, TalkingData, and Baidu Analytics1
. These analytics SDKs enable device fingerprinting and create extensive user profiles for user behavior tracking2
.What makes these malicious Microsoft VSCode AI extensions particularly dangerous is their legitimate functionality. Both tools provide autocomplete suggestions and explain coding errors as promised, effectively avoiding detection while exfiltrated sensitive user data flows to servers in China
1
2
. This dual-purpose design means developers receive genuine value from the extensions while unknowingly exposing proprietary code, intellectual property, and potentially sensitive client information. Microsoft told BleepingComputer it was investigating the situation, but the extensions remained available for download at the time of reporting.Related Stories
Koi Security also disclosed six zero-day vulnerabilities in JavaScript package managers including npm, pnpm, vlt, and Bun, collectively named PackageGate Flaws
1
. These vulnerabilities allow attackers to bypass security controls designed to prevent automatic execution of lifecycle scripts during package installation, undermining defenses against supply chain attacks1
. While pnpm addressed the issues in version 10.26.0 (tracking them as CVE-2025-69264 with a CVSS score of 8.8 and CVE-2025-69263 with a CVSS score of 7.5), vlt patched in version 1.0.0-rc.10, and Bun fixed them in version 1.3.5, npm declined to address the vulnerability1
. Security researcher Oren Yomtov cautioned that "until PackageGate is fully addressed, organizations need to make their own informed choices about risk"1
. Developers should watch for Visual Studio Marketplace policy changes and consider implementing additional vetting processes for extensions, particularly those offering AI assistance, as the intersection of convenience and security continues to present challenges in the development ecosystem.🟡 untrained:Summarized by
Navi
[1]
07 Jan 2026•Technology

17 Jun 2026•Technology

12 Feb 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
