Malicious VS Code Extensions Deliver XWorm via Marketplace
cyb3rops · x · 2026-08-11
Security researchers have identified a threat actor continuously uploading malicious extensions containing XWorm malware to the VS Code Marketplace.
The extension activates on startup and displays a deceptive prompt requesting elevated permissions. Once granted admin rights, it fetches an encoded PowerShell command from its C2 server, creates a hidden directory, and adds itself to Microsoft Defender's exclusion list to evade detection before downloading and executing a payload disguised as svchost.exe.
More from coding & agent
- Open-source framework runs 20+ Claude Code agents in parallel for automated bug fixing and best practices — tom_doerr · 2026-08-11
- Call for Testing Third-Party Models Across Zcode, Kimi, and Grok Build — teortaxesTex · 2026-08-11
- Turn Code Repos into Promo Videos in 10 Mins with Grok CLI and hyperframes — sujingshen · 2026-08-11
- Uber Burned 2026 AI Budget in 4 Months, Then Cut Token Costs via 4 Optimizations — femke_plantinga · 2026-08-11
- Developer Jokes About Becoming Claude's QA: The Reality of AI Pair Programming — dejavucoder · 2026-08-11
- DeepDoc: Open-Source AI Tool for Deep Research on Local Documents — tom_doerr · 2026-08-11