Malicious Microsoft VSCode AI extensions could have affected more than 1.5 million users



  • Two VSCode extensions extracted sensitive user data to Chinese servers
  • ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined
  • The extensions used iframes, commands, and hidden SDKs to steal files and track activity.

More than 1.5 million people may have had their sensitive data leaked to Chinese hackers via two malicious extensions found on the VSCode Marketplace.

Security researchers at Koi Security said they discovered two malicious browser extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace, Microsoft’s official store for code editing plugins.



Leave a Comment

Your email address will not be published. Required fields are marked *