A malicious AI-created extension with ransomware capabilities sneaks into Microsoft’s official VS Code marketplace, so developers beware



  • Malicious VS Code extension ‘susvsex’ acted as ransomware and used GitHub for command control
  • The extension appeared generated by AI, with embedded decryption keys and suspicious metadata
  • Microsoft removed it after public pressure, raising concerns about gaps in the market review.

A malicious extension was published on Microsoft’s official VS Code marketplace and was able to remain there for some time collecting downloads and infecting people’s computers.

Security researcher John Tuckner of Secure Annex found and reported the extension to Microsoft, noting that the extension functioned as ransomware and, to make matters worse, made it “blatantly malicious” by stating, in the description, exactly what it does: “VS Code extension that automatically compresses, uploads and encrypts files from C:UsersPublictesting on Windows.”



Leave a Comment

Your email address will not be published. Required fields are marked *