Malicious code in millions of installs traced to Microsoft Visual Studio

A group of Israeli researchers found thousands of potentially harmful extensions on the Visual Studio Code (VSCode) Marketplace, with some having millions of downloads. The researchers created a fake extension mimicking the popular ‘Dracula Official’ theme, dubbed ‘Darcula’, which included risky code to collect system information. This extension was downloaded by multiple high-value targets, including a publicly listed company and major security firms.

Using a custom tool called ‘ExtensionTotal’, the researchers discovered 1,283 extensions with known malicious code, 8,161 communicating with hardcoded IP addresses, and 1,452 running unknown executables. Despite reporting these findings to Microsoft, many of these extensions remained available for download as little as a day ago.

The researchers warn that the lack of stringent security controls on the VSCode Marketplace poses a significant threat to organizations.

 

Top Stories

Related Articles

May 12, 2026 Θα έχετε την καλύτερη εντύπωση για το Wildsino αν παίξετε αυτά τα παιχνίδια στο tablet σας ή σε more...

May 12, 2026 Te softwarematige kansspelen zorgt gij ontwikkelaar pro diegene gij RTP klopt, gezag narekenen of de achterliggende algoritmen wa more...

May 11, 2026 Most other intimate source, such as other kid, Disregard Holtz, affirmed he could be “ 11may however fighting more...

May 11, 2026 Government said Monday he's investigating the fresh disappearance from Nancy Guthrie, mom from "Today" host Savannah Guthrie, as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.