216.73.216.6

VS Code Extension Impersonating Zoom Targets Google Chrome Cookies

· Published 21/01/2025 22:17 · Modified 22/01/2025 09:16

Export JSON

Essential information

Published
21/01/2025 22:17
Modified
22/01/2025 09:16
Tags
2025-01-21 cookies vs code zoom
Related entities
3 observables, 8 techniques (mitre), 1 others

Description

A malicious Visual Studio Code extension masquerading as a application was discovered, designed to access and steal Google Chrome . The extension, uploaded to the Marketplace on November 30 and updated on December 8, impersonates the Workspace tool to gain users' trust. It contains code targeting Google Chrome , introduced in version 0.2.2. The extension attempts to fetch data from a suspicious endpoint hosted in China and access Chrome's cookie storage and Windows registry data. This incident highlights the ongoing threat of malicious actors exploiting trusted infrastructure to distribute malware through seemingly legitimate channels, revealing vulnerabilities within the extension ecosystem.

External references