Malicious Microsoft VSCode AI extensions may have affected more than 1.5 million users


  • Two VSCode extensions exfiltrated sensitive user data to Chinese servers
  • ChatGPT – 中文版 and ChatMoss have totaled over 1.5 million installs
  • Extensions used hidden iframes, commands, and SDKs to steal files and track activity

More than 1.5 million people may have had their sensitive data exfiltrated to Chinese hackers via two malicious extensions found on the VSCode Marketplace.

Security researchers at Koi Security said they discovered two malicious browser extensions on Microsoft’s Visual Studio Code (VSCode) Marketplace, the official Microsoft store for code editor add-ons.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top