Malicious AI-created extension with ransomware capabilities sneaks into Microsoft’s official VS Code marketplace – so developers beware


  • VS Code malicious extension “susvsex” acted as ransomware and used GitHub for order control
  • The extension appears to be AI-generated, with embedded decryption keys and suspicious metadata
  • Microsoft removed it under public pressure, raising concerns about shortcomings in market assessment.

A malicious extension was published on Microsoft’s official VS Code marketplace and was able to stay there for some time, gathering downloads and infecting users’ computers.

Security researcher John Tuckner of Secure Annex found and reported the extension to Microsoft, noting that the extension functioned like ransomware and, to make matters worse, made it “obviously malicious” by stating, in the description, exactly what it does: “VS Code extension that automatically compresses, downloads, and encrypts files from C:UsersPublictesting on Windows.” »

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top