Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    CelcomDigi introduces Prepaid 5G Hyper and Prepaid 5G Power

    Apple releases new AirTag with improved location precision

    Google Chrome wants to surf the web for you

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026

      Ashley St. Clair, the mother of one of Elon Musk’s children, sues xAI over Grok sexual images

      January 17, 2026

      Anthropic joins OpenAI’s push into health care with new Claude tools

      January 12, 2026

      The mother of one of Elon Musk’s children says his AI bot won’t stop creating sexualized images of her

      January 7, 2026

      A new pope, political shake-ups and celebs in space: The 2025-in-review news quiz

      December 31, 2025
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      Large XRP Whales Sold $800 Million, Will Price Drop Again?

      January 28, 2026

      EMCD x BeInCrypto Webinar Recap: Inflation, Volatility, and Practical Frameworks for Safer Crypto Decisions

      January 28, 2026

      What Does Retail Attention Rotating to Safe Havens Mean for a Potential Silver Top?

      January 28, 2026

      How January’s Sharp Decline in Spot Volume Is Threatening the Crypto Market Structure

      January 28, 2026

      What To Expect From Solana Price In February 2026?

      January 28, 2026
    • Technology

      Google Chrome wants to surf the web for you

      January 28, 2026

      Looking for streaming deals? Try hitting the cancel button

      January 28, 2026

      Windows 11 will soon let you pick up Android apps where you left off

      January 28, 2026

      Take $700 off this giant LG OLED ultrawide gaming monitor

      January 28, 2026

      Latest Windows update kills dial-up modems… intentionally

      January 28, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»VSCode extensions found downloading early-stage ransomware
    Technology

    VSCode extensions found downloading early-stage ransomware

    TechAiVerseBy TechAiVerseMarch 23, 2025No Comments3 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    VSCode extensions found downloading early-stage ransomware
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    VSCode extensions found downloading early-stage ransomware

    Two malicious VSCode Marketplace extensions were found deploying in-development ransomware, exposing critical gaps in Microsoft’s review process.

    The extensions, named “ahban.shiba” and “ahban.cychelloworld,” were downloaded seven and eight times, respectively, before they were eventually removed from the store.

    It is notable that the extensions were uploaded onto the VSCode Marketplace on October 27, 2024 (ahban.cychelloworld) and February 17, 2025 (ahban.shiba), bypassing safety review processes and remaining on Microsoft’s store for an extensive period of time.

    The VSCode Marketplace is an online platform where developers can find, install, and share extensions for Visual Studio Code (VSCode). It is widely used by software and web developers, data scientists, and programmers.

    ReversingLabs discovered that the two extensions contain a PowerShell command that downloads and executes another PS script that acts as ransomware from a remote server hosted on Amazon AWS.

    The ransomware is clearly in development or a test as it only encrypts files in the C:users%username%DesktoptestShiba folder and does not touch any other files.

    When done encrypting the files, the script will display a Windows alert stating, “Your files have been encrypted. Pay 1 ShibaCoin to ShibaWallet to recover them.” No ransom notes or further instructions are given like normal ransomware attacks.

    Malicious PowerShell script
    Source: ReversingLabs

    ReversingLabs states that Microsoft quickly removed the two extensions from the VSCode Marketplace after the researchers reported them.

    However, ExtensionTotal security researcher Italy Kruk told BleepingComputer that their automated scanner caught the extensions earlier and informed Microsoft a while back, receiving no response.

    Kruk explains that ahban.cychelloworld wasn’t malicious in its initial upload. It added the ransomware code in its second submission, version 0.0.2, which was accepted on the VSCode Marketplace on November 24, 2024.

    “We reported ahban.cychelloworld to Microsoft on November 25, 2024, via an automatic report generated by our scanner,” Kruk told BleepingComputer.

    “It is possible that due to the low number of installs for the offending extension, Microsoft didn’t prioritize its review.”

    Since then, the ahban.cychelloworld extension had another five releases, all containing the malicious code and all being accepted in Microsoft’s store.

    The fact that the extensions downloaded and executed remote PowerShell scripts, and could stay undetected for almost four months demonstrates a concerning gap in Microsoft’s review process.

    Although in this case, Microsoft failed to react for months, the company has done the opposite recently, removing VSCode themes used by 9 million users too quickly after it got reported for suspicious obfuscated code.

    While VSCode themes should not be using obfuscated JavaScript, the Material Theme – Free’ and ‘Material Theme Icons – Free’ extensions were later proven not to be malicious.

    Microsoft apologized for the unjustified removal and banning of their publisher and said they would update their “scanners and investigation process to reduce the likelihood of another event like this.”


    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleJonah Peretti helped shaped digital media — can he do it again?
    Next Article CISA tags NAKIVO backup flaw as actively exploited in attacks
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Google Chrome wants to surf the web for you

    January 28, 2026

    Looking for streaming deals? Try hitting the cancel button

    January 28, 2026

    Windows 11 will soon let you pick up Android apps where you left off

    January 28, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025643 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025241 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025143 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Gadgets January 29, 2026

    CelcomDigi introduces Prepaid 5G Hyper and Prepaid 5G Power

    CelcomDigi introduces Prepaid 5G Hyper and Prepaid 5G Power CelcomDigi has refreshed its prepaid lineup in Malaysia with…

    Apple releases new AirTag with improved location precision

    Google Chrome wants to surf the web for you

    Looking for streaming deals? Try hitting the cancel button

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    CelcomDigi introduces Prepaid 5G Hyper and Prepaid 5G Power

    January 29, 20262 Views

    Apple releases new AirTag with improved location precision

    January 29, 20263 Views

    Google Chrome wants to surf the web for you

    January 28, 20263 Views
    Most Popular

    A Team of Female Founders Is Launching Cloud Security Tech That Could Overhaul AI Protection

    March 12, 20250 Views

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.