Edit 2025-04-09 16:42Z - article was updated with a tenth package (Prettier - Code)
A set of ten VSCode extensions on Microsoft’s Visual Studio Code Marketplace pose as legitimate development tools while infecting users with the XMRig cryptominer for Monero.
ExtensionTotal researcher Yuval Ronen has uncovered ten VSCode extensions published on Microsoft’s portal on April 4, 2025.
The package names are:
- Prettier - Code for VSCode (by prettier) - 486K installs
- Discord Rich Presence for VS Code (by
Mark H
) - 189K installs- Rojo – Roblox Studio Sync (by
evaera
) - 117K installs- Solidity Compiler (by
VSCode Developer
) - 1.3K installs- Claude AI (by
Mark H
)- Golang Compiler (by
Mark H
)- ChatGPT Agent for VSCode (by
Mark H
)- HTML Obfuscator (by
Mark H
)- Python Obfuscator for VSCode (by
Mark H
)- Rust Compiler for VSCode (by
Mark H
)
Let this be a lesson. We should never, ever, use software.
Software is the leading cause of all computer viruses.
All people who use software will fucking die, smh.
Microsoft and macro viruses, name a more iconic duo.
Oh Hi Mark
Can your Linux do that?
.
.
.
.
.
.
.
.
Yes, of couse it can, all of that and even more!
Kate >>> VSCode
Who is Kate?
Kate the editor? Or is there an IDE called Kate?
Yo, @drspod@lemmy.ml, check the article again. Prettier, a very popular extension, heads the list now:
Prettier — Code for VSCode (by prettier) – 955K Installs Discord Rich Presence for VS Code (by Mark H) – 189K Installs Rojo — Roblox Studio Sync (by evaera) – 117K Installs Solidity Compiler (by VSCode Developer) – 1.3K Installs Claude AI (by Mark H) Golang Compiler (by Mark H) ChatGPT Agent for VSCode (by Mark H) HTML Obfuscator (by Mark H) Python Obfuscator for VSCode (by Mark H) Rust Compiler for VSCode (by Mark H)
Thanks, I’ve updated the description text.
shocker. an electron app that’s terrible and full of malware.
Don’t think it has anything to do with electron. VSCode is just the largest editor that people install extensions for, so it’s what makes the most sense to write malware for. If vim was more popular, I’m sure there would be more crypto mining extensions for that (I wonder how many there are? Surely more than zero?)
It also helps its as easy as clicking a button to install an extension… and i wonder how many even bother checks the source of the extension?