Developers Targeted Through Poisoned VS Code Extensions
Weaponised Visual Studio Code extensions silently infected developer machines, stealing credentials, system data, and cryptocurrency at scale.
Source: Trend Micro
Read more: CyberSecBrief
seen from China

seen from United States

seen from Netherlands

seen from Sweden

seen from Türkiye
seen from United States
seen from Netherlands
seen from Vietnam
seen from United States
seen from Hong Kong SAR China
seen from Taiwan
seen from United Kingdom

seen from Germany

seen from Malaysia

seen from Türkiye
seen from China

seen from United States
seen from Russia

seen from Türkiye
seen from United Kingdom
Developers Targeted Through Poisoned VS Code Extensions
Weaponised Visual Studio Code extensions silently infected developer machines, stealing credentials, system data, and cryptocurrency at scale.
Source: Trend Micro
Read more: CyberSecBrief
Malicious npm Packages Hijack Crypto Keys
Five npm packages typosquatting Solana and Ethereum libraries exfiltrate private keys to a Telegram bot, putting developers’ cryptocurrency wallets at high risk.
Source: Socket
Read more: CyberSecBrief
One Click to Compromise: Cursor IDE Deeplink Exploit Emerges
A crafted phishing link can trick developers into installing a malicious MCP configuration in Cursor IDE, executing attacker commands and even spawning reverse shells with user-level privileges.
Source: Proofpoint
Read more: CyberSecBrief
NuGet Packages Targeted by Automated Malicious Cloning
Researchers discovered automated scripts in NuGet packages that clone, modify, and inflate malicious library downloads, posing supply-chain risks for developers.
Source: ReversingLabs
Read more: CyberSecBrief
GitHub Codespaces Flaw Lets Attackers Execute Code
Default VS Code configurations in GitHub Codespaces enable attackers to trigger remote code execution via malicious repositories or pull requests, risking token and secret theft.
Source: Orca Security
Read more: CyberSecBrief
crates.io Pushes Security Upstream for Developers
The Rust package registry is surfacing vulnerability data earlier and tightening risky publishing paths to reduce supply-chain exposure.
Source: Socket
Read more: CyberSecBrief
Popular VS Code AI Tools Secretly Exfiltrate Source Code
Malicious Visual Studio Code extensions quietly siphoned full projects and edits from up to 1.5 million developers.
Source: Koi
Read more: CyberSecBrief