World News

Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users

https://www.profitableratecpm.com/f4ffsdxe?key=39b1ebce72f3758345b2155c98e6709c

  • Two VSCode extensions exfiltrated sensitive user data to Chinese servers
  • ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined
  • Extensions used hidden iframes, commands, and SDKs to steal files and track activity

More than 1.5 million people may have had their sensitive data exfiltrated to Chinese hackers through two malicious extensions found on the VSCode Marketplace.

Security researchers at Koi Security said they discovered two malicious browser extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace, the official Microsoft store for code editor add-ons.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button