Malicious AI-Made Extension With Ransomware Features Sneaks Onto Microsoft’s Official VS Code Marketplace – So Developers Beware


  • Malicious VS code extension ‘susvsex’ acted as ransomware and used GitHub for command control
  • The extension appeared to be AI-generated with embedded decryption keys and suspicious metadata
  • Microsoft removed it after public pressure, raising concerns about gaps in marketplace reviews

A malicious extension was published on Microsoft’s official VS Code marketplace and was able to remain there for some time, collecting downloads and infecting people’s computers.

Security researcher John Tuckner of Secure Annex found and reported the extension to Microsoft, noting that the extension acted as ransomware and, to make matters worse, made it “obviously malicious” by stating, in the description, exactly what it does: “VS code extension that automatically zips, uploads, and encrypts files from C:UsersPublictesting on Windows.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top