Cybersecurity researchers have uncovered a new threat targeting developers using Visual Studio Code (VS Code).
A malicious extension masquerading as a Zoom app has been discovered stealing cookies from Google Chrome, raising concerns about the security of the VS Code extension ecosystem.
The deceptive extension, uploaded to the VS Code Marketplace on November 30, 2024, and last updated on December 8, impersonates the Zoom Workspace tool.
To enhance its credibility, the uploader included a link to the legitimate GitHub repository for the Zoom Meeting SDK.
The malicious extension’s core functionality is contained in two main files:-
Researchers at Hunt.io identified that the extension is activated using the “onStartupFinished” event in the package.json file, ensuring that any malicious code runs once VS Code has fully loaded.
Key Components:-
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
An SQL query is used to extract sensitive information from the Chrome cookies database:-
SELECT host_key, name, encrypted_value, path, expires_utc, is_secure, is_httponly, creation_utc, has_expires, is_persistent FROM cookies This query retrieves various cookie attributes, including encrypted values, expiration dates, and security flags.
The extension was initially released as versions 0.2.0 and 0.2.1 on November 30, with the code targeting Google Chrome cookies introduced in version 0.2.2 on December 8. This suggests a deliberate strategy to bypass early detection mechanisms.
This discovery highlights the potential security risks associated with VS Code extensions. Developers are advised to:
Cybersecurity experts have reported the malicious extension to the Microsoft VS Code Marketplace to protect users.
As IDEs like VS Code continue to be essential tools for developers, maintaining vigilance and implementing robust security practices becomes increasingly crucial to safeguard sensitive data and maintain the integrity of software development processes.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…