Damaging Microsoft VS Code extensions could cause major damage for millions of users

Hacker
Image Credit: Geralt / Pixabay (Image credit: Image Credit: Geralt / Pixabay)

Researchers appear to have found another avenue in which to slam Microsoft for its poor cybersecurity practices - this time around, it’s the marketplace for Visual Studio Code.

Visual Studio Code (often abbreviated as VS Code) is a free, open source code editor developed by Microsoft designed for developing and debugging modern web and cloud applications. With 14 million users, VS Code is extremely popular, thanks mostly to its robust features, such as cross-platform availability, extensibility, built-in Git support, IntelliSense, debugging, integrated terminal, and customization.

As reported by BleepingComputer, researchers Amit Assaraf, Itay Kruk, and Idan Dardikman set out to see how easy it would be to compromise VS Code users, so they created a typosquatted version of the popular “Dracula Official” theme. Dracula is a theme designed to be visually appealing while reducing eye strain for developers.

Darcula strikes

They named the theme “Darcula” and even bought a domain, darculatheme.com, with which they were able to become a verified publisher on the marketplace. The theme worked almost identical to the legitimate one, but also carried malicious code which was able to steal sensitive information from the victims.

Unfortunately, the experiment was a resounding success, with many companies soon mistakenly downloading it. Among the victims was an unnamed, publicly listed company with a $483 billion market cap. Other notable mentions include a national justice court network, and a couple of large security companies. 

This prompted the researchers to take it a step further and see if other criminals thought of the same thing before them, and lo and behold - they found 1,283 extensions with known malicious code. Cumulatively, they had 229 million installs. They also found 8,161 extensions communicating with hardcoded IP addresses, 1,452 running unknown executables, and 2,304 that are using another publisher's Github repo.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
hacker.jpeg
VSCode extensions pulled over security risks, but millions of users have already installed
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Microsoft reveals over a million PCs hit by malvertising campaign
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras