Malicious VS Code Extensions Deliver XWorm via Marketplace

cyb3rops · x · 2026-08-11

Security researchers have identified a threat actor continuously uploading malicious extensions containing XWorm malware to the VS Code Marketplace.

The extension activates on startup and displays a deceptive prompt requesting elevated permissions. Once granted admin rights, it fetches an encoded PowerShell command from its C2 server, creates a hidden directory, and adds itself to Microsoft Defender's exclusion list to evade detection before downloading and executing a payload disguised as svchost.exe.

Original post →

More from coding & agent

coding & agent channel →