Malicious “Ransomvibing” Extension Infects Visual Studio Code Marketplace
Security researchers uncovered a Visual Studio Code extension dubbed “Ransomvibing” that encrypted user files and exfiltrated data while managing to pass marketplace review. The extension contained hard-coded decryption keys and simple Python and Node decryptors, indicating unsophisticated but dangerous behavior. The incident exposes major weaknesses in extension marketplace security and highlights how trusted development environments can be exploited to distribute ransomware-like payloads to unsuspecting developers.
https://www.darkreading.com/application-security/ransomvibing-infests-visual-studio-extension-market
Comments
Post a Comment