More

    Malicious Microsoft VSCode AI extensions might have hit over 1.5 million users



    • Two VSCode extensions exfiltrated sensitive user data to Chinese servers
    • ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined
    • Extensions used hidden iframes, commands, and SDKs to steal files and track activity

    More than 1.5 million people may have had their sensitive data exfiltrated to Chinese hackers through two malicious extensions found on the VSCode Marketplace.

    Security researchers at Koi Security said they discovered two malicious browser extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace, the official Microsoft store for code editor add-ons.


    https://cdn.mos.cms.futurecdn.net/X5DPDeFcG3TSkqdJMgSU3U-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img