threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto wallets, API keys, and SSH keys. The malware employs advanced obfuscation techniques to evade detec… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
vulnerability Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execut… SecurityWeek · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958USaivscodecredentials
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process A security researcher, Ammar Askar, released a GitHub token-stealing exploit for Microsoft's VS Code, citing frustration with the company's vulnerability disclosure process. This follows a recent breach of GitHub reposit… The Record · Jun 4, 2026 High githubvulnerabilitydisclosure
vulnerability VS Code zero-day lets hackers steal GitHub tokens in one click A researcher, Ammar Askar, has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. The vulne… BleepingComputer · Jun 3, 2026 High zero-daygithubvscode
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
threat-intel GitHub Confirms Breach, 4K Internal Repos Stolen GitHub experienced a data breach where approximately 4,000 internal code repositories were stolen by the threat actor TeamPCP. The breach originated from a poisoned VS Code extension compromising an employee's device, an… Dark Reading · May 20, 2026 High vscodeopen sourcedeveloper tooling
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer
supply-chain GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub experienced a breach affecting approximately 3,800 internal repositories after an employee installed a malicious VS Code extension. The incident is linked to a broader supply chain attack by TeamPCP, who are deman… BleepingComputer · May 20, 2026 High supply chainvscodeextension
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode