{"id":5850,"date":"2026-01-21T07:08:07","date_gmt":"2026-01-21T07:08:07","guid":{"rendered":"https:\/\/areeblog.com\/?p=5850"},"modified":"2026-01-21T07:08:07","modified_gmt":"2026-01-21T07:08:07","slug":"how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials","status":"publish","type":"post","link":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/","title":{"rendered":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials"},"content":{"rendered":"<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"5851\" data-permalink=\"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/img-20260121-wa0002\/\" data-orig-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg\" data-orig-size=\"1280,853\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"IMG-20260121-WA0002\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-1024x682.jpg\" class=\"aligncenter size-full wp-image-5851\" src=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg\" alt=\"How Malicious VS Code Extensions Are Used to Steal Developer Credentials\" width=\"1280\" height=\"853\" srcset=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg 1280w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-300x200.jpg 300w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-1024x682.jpg 1024w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-768x512.jpg 768w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-330x220.jpg 330w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-420x280.jpg 420w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-615x410.jpg 615w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002-860x573.jpg 860w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p>Developers trust their tools. That trust is what makes Visual Studio Code a productive workspace, and what attackers are quietly <a href=\"https:\/\/areeblog.com\/common-mfa-bypass-techniques-attackers-use-today\/\">exploiting<\/a>.<\/p>\n<p>Recent <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/a\/analysis-of-the-evelyn-stealer-campaign.html\">security research<\/a> shows a worrying trend: threat actors are slipping malicious code into what look like helpful VS Code extensions.<\/p>\n<p>When a developer installs one of these packages, the extension can drop a tiny downloader, reach out to an attacker-controlled server, and pull a second piece that expands into a full-fledged information stealer or remote access tool.<\/p>\n<figure id=\"attachment_5852\" aria-describedby=\"caption-attachment-5852\" style=\"width: 960px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"5852\" data-permalink=\"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/evelyn-stealer_fig01\/\" data-orig-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/evelyn-stealer_fig01.png\" data-orig-size=\"960,332\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"evelyn-stealer_fig01\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Attack chain of the Evelyn campaign. Source: Trend Micro&lt;\/p&gt;\n\" data-large-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/evelyn-stealer_fig01.png\" class=\"size-full wp-image-5852\" src=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/evelyn-stealer_fig01.png\" alt=\"Attack chain of the Evelyn campaign\" width=\"960\" height=\"332\" srcset=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/evelyn-stealer_fig01.png 960w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/evelyn-stealer_fig01-300x104.png 300w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/evelyn-stealer_fig01-768x266.png 768w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/evelyn-stealer_fig01-860x297.png 860w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><figcaption id=\"caption-attachment-5852\" class=\"wp-caption-text\">Attack chain of the Evelyn campaign. Source: Trend Micro<\/figcaption><\/figure>\n<p>Multiple vendors and independent researchers have documented active campaigns that used the extension ecosystem as an entry point for multi-stage malware.<\/p>\n<p>The final payloads harvest browser credentials, development secrets, and other data that can let an intruder move from one developer machine into broader systems. I\u2019ll walk through the typical attack chain in plain terms, then give realistic, usable guidance you can act on today.<\/p>\n<h2>How Malicious VS Code Extensions Reach Developers<\/h2>\n<p>Most people discover extensions the same way: through the Marketplace, GitHub, or a link shared by a colleague. Attackers copy that pattern and build trust by mimicking popular tools or publishers. They use techniques like typosquatting (a nearly identical name), fake publisher profiles, or packaging a small, seemingly useful feature with hidden code. In some campaigns, researchers found that extensions carried what looked like harmless image files or helper libraries that in fact contained encoded binaries.<\/p>\n<p>Some extensions are uploaded directly to the official VS Code Marketplace; others land on alternative registries or GitHub and rely on users to install them manually. Once installed, an extension runs with the permissions available to VS Code and can execute Node.js code, shell out to the system, or write files under the user profile. That makes extensions a convenient launch point for a small downloader that contacts an attacker host and retrieves the next stage.<\/p>\n<h2>What happens after a malicious VS Code extension runs<\/h2>\n<p>A common pattern is multistage delivery. The extension\u2019s initial code is typically small: it writes a file into a temporary folder or invokes a brief PowerShell or Node command to fetch another artifact. The second artifact is heavier, a loader that decrypts and injects a final payload directly into memory or into a running process.<\/p>\n<p>By avoiding obvious disk footprints and using in-memory execution techniques, attackers make detection harder for traditional antivirus. Vendors have observed these loaders performing tasks such as capturing browser cookies, reading SSH keys and <code>.git<\/code> files, logging clipboard data, and taking screenshots.<\/p>\n<p>Attackers also use public hosting like GitHub raw content, fast-changing domains, or even <a href=\"https:\/\/areeblog.com\/ssh-and-terminal\/\">FTP servers<\/a> as their control channels. Frequent rotation of payloads and short-lived repositories are deliberate: they reduce the opportunity for defenders to produce lasting signatures. Some campaigns include anti-analysis checks, the code looks for virtual machines, debuggers, or sandbox environments and delays or alters behavior if it suspects it\u2019s being analyzed.<\/p>\n<h2>Why Developers and Organizations Should Pay Attention<\/h2>\n<p>When a developer machine is compromised, the effects can ripple outward. Developer workstations typically have keys, tokens, and connections to code repositories and cloud platforms.<\/p>\n<p>An attacker who harvests a GitHub personal access token, SSH key, or stored credentials can access source, modify build scripts, or introduce backdoors. The compromise may begin as a single infected extension, but it can quickly become a foothold for supply chain abuse and lateral movement. Reports from multiple research groups have linked extension-based attacks to credential theft and broader intrusions.<\/p>\n<h2>Steps for Teams and Individual Developers<\/h2>\n<p>Addressing this requires both policy and habit changes. Here are practical measures that reduce exposure without blocking legitimate work:<\/p>\n<ul>\n<li>Treat extension installs like software installs. In teams, use a curated list or a private extension gallery and restrict installs on sensitive developer machines. Enterprises can host a private extension marketplace and rehost trusted public extensions after a vetting step. That approach limits the attack surface while preserving developer productivity.<\/li>\n<li>Monitor and log extension lifecycle events. Capture telemetry when extensions are installed, updated, or when they write executables to user profile directories. Centralized logs help you spot a pattern \u2014 for example, an extension that immediately drops a DLL into Temp and spawns a PowerShell process with encoded commands.<\/li>\n<li>Harden endpoint controls. Use application allowlisting and tools that detect in-memory injection patterns (EDR solutions that surface CreateProcess with CREATE_SUSPENDED, WriteProcessMemory, or reflective DLL loads). Limit PowerShell to constrained modes and instrument its logging so suspicious download-and-execute chains are visible.<\/li>\n<li>Protect developer secrets. Avoid storing tokens and credentials in plain files. Prefer hardware-backed keys or platform secret managers, and enable short-lived tokens where possible. Scan repositories and package manifests for accidental secrets and remove them.<\/li>\n<li>Educate the team with relevant examples. Show engineers how a fake \u201cformatter\u201d or \u201ctheme\u201d could contain hidden code. Practical, example-driven training (using anonymized excerpts from real reports) helps engineers make better installation choices without becoming overly suspicious.<\/li>\n<\/ul>\n<h2>What Defenders Should Hunt for now<\/h2>\n<p>There are high-value signals that usually appear early in these attacks. Look for extensions that create or modify executable files under <code>%TEMP%<\/code> or the user profile and then spawn interpreter processes with download flags.<\/p>\n<p>Track network requests to raw content on public code hosts or to obscure domains and FTP servers. Alert on processes that write to browser profile directories or read known locations for SSH keys and <code>.git<\/code> metadata from non-browser, non-git processes, those are strong signals of data collection.<\/p>\n<p>Vendors who tracked recent campaigns provide IoCs and behavioral signatures that teams can fold into SIEM and EDR rules.<\/p>\n<h2>How to Set Policy Without Slowing Engineering Down<\/h2>\n<p>The worst outcome is either unlimited installs with no oversight, or rigid bans that frustrate developers. A balanced approach works best:<\/p>\n<ul>\n<li>Curate a short list of approved, battle-tested extensions and offer an easy process to request additions.<\/li>\n<li>Use a private marketplace for sensitive teams and a monitored approval flow for general engineering.<\/li>\n<li>Implement telemetry that can be turned into lightweight, automated checks rather than manual gates. That way, engineers keep momentum and security gains visibility. Microsoft and other tooling providers document how enterprises can host and manage private extension catalogs; those guides include scripts and configuration examples to automate rehosting and deployment.<\/li>\n<\/ul>\n<h2>Stay Practical and Proactive<\/h2>\n<p>Malicious VS Code extensions are a clear example of attackers exploiting trusted workflows, not new zero-day wizardry. The fixes are straightforward but require coordination: vet extensions, protect secrets, monitor the right signals, and give developers a simple path to install tools they need.<\/p>\n<p>Security teams should integrate extension visibility into existing endpoint and log monitoring, while engineering leads should champion safe install practices. The effort is manageable, and the payoff is preventing a single compromised tool from turning into a larger breach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Developers trust their tools. That trust is what makes Visual Studio Code a productive workspace, and what attackers are quietly exploiting. Recent security research shows a worrying trend: threat actors are slipping malicious code into what look like helpful VS Code extensions. When a developer installs one of these packages, the extension can drop a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5851,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_monsterinsights_skip_tracking":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[14],"tags":[1066],"class_list":["post-5850","post","type-post","status-publish","format-standard","has-post-thumbnail","category-cybersecurity","tag-vs-code"],"share_on_mastodon":{"url":"https:\/\/mastodon.social\/@Areeblog\/115931847266571517","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How Malicious VS Code Extensions Are Used to Steal Developer Credentials - Aree Blog<\/title>\n<meta name=\"description\" content=\"How malicious VS Code extensions steal developer credentials, abuse trust, and expose tokens, passwords, and source code.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Malicious VS Code Extensions Are Used to Steal Developer Credentials\" \/>\n<meta property=\"og:description\" content=\"How malicious VS Code extensions steal developer credentials, abuse trust, and expose tokens, passwords, and source code.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/\" \/>\n<meta property=\"og:site_name\" content=\"Aree Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-21T07:08:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Daniel Chinonso John\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Chinonso John\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/\"},\"author\":{\"name\":\"Daniel Chinonso John\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"headline\":\"How Malicious VS Code Extensions Are Used to Steal Developer Credentials\",\"datePublished\":\"2026-01-21T07:08:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/\"},\"wordCount\":1131,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260121-WA0002.jpg\",\"keywords\":[\"VS Code\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/\",\"url\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/\",\"name\":\"How Malicious VS Code Extensions Are Used to Steal Developer Credentials - Aree Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260121-WA0002.jpg\",\"datePublished\":\"2026-01-21T07:08:07+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"description\":\"How malicious VS Code extensions steal developer credentials, abuse trust, and expose tokens, passwords, and source code.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#primaryimage\",\"url\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260121-WA0002.jpg\",\"contentUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260121-WA0002.jpg\",\"width\":1280,\"height\":853,\"caption\":\"How Malicious VS Code Extensions Are Used to Steal Developer Credentials\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/areeblog.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Malicious VS Code Extensions Are Used to Steal Developer Credentials\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\",\"url\":\"https:\\\/\\\/areeblog.com\\\/\",\"name\":\"Aree Blog\",\"description\":\"Unfiltered Perspectives, Unstoppable Insights\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/areeblog.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\",\"name\":\"Daniel Chinonso John\",\"description\":\"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/daniel-john-45183a169\\\/\"],\"url\":\"https:\\\/\\\/areeblog.com\\\/author\\\/danojohn55gmail-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials - Aree Blog","description":"How malicious VS Code extensions steal developer credentials, abuse trust, and expose tokens, passwords, and source code.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/","og_locale":"en_US","og_type":"article","og_title":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials","og_description":"How malicious VS Code extensions steal developer credentials, abuse trust, and expose tokens, passwords, and source code.","og_url":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/","og_site_name":"Aree Blog","article_published_time":"2026-01-21T07:08:07+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg","type":"image\/jpeg"}],"author":"Daniel Chinonso John","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Daniel Chinonso John","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#article","isPartOf":{"@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/"},"author":{"name":"Daniel Chinonso John","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"headline":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials","datePublished":"2026-01-21T07:08:07+00:00","mainEntityOfPage":{"@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/"},"wordCount":1131,"commentCount":0,"image":{"@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg","keywords":["VS Code"],"articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/","url":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/","name":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials - Aree Blog","isPartOf":{"@id":"https:\/\/areeblog.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#primaryimage"},"image":{"@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg","datePublished":"2026-01-21T07:08:07+00:00","author":{"@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"description":"How malicious VS Code extensions steal developer credentials, abuse trust, and expose tokens, passwords, and source code.","breadcrumb":{"@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#primaryimage","url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg","contentUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg","width":1280,"height":853,"caption":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials"},{"@type":"BreadcrumbList","@id":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/areeblog.com\/"},{"@type":"ListItem","position":2,"name":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials"}]},{"@type":"WebSite","@id":"https:\/\/areeblog.com\/#website","url":"https:\/\/areeblog.com\/","name":"Aree Blog","description":"Unfiltered Perspectives, Unstoppable Insights","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/areeblog.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63","name":"Daniel Chinonso John","description":"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.","sameAs":["https:\/\/www.linkedin.com\/in\/daniel-john-45183a169\/"],"url":"https:\/\/areeblog.com\/author\/danojohn55gmail-com\/"}]}},"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6701,"url":"https:\/\/areeblog.com\/shadow-ai-is-moving-into-approved-enterprise-tools\/","url_meta":{"origin":5850,"position":0},"title":"Shadow AI Is Moving Into Approved Enterprise Tools","author":"Samuel Ogori","date":"August 31, 2026","format":false,"excerpt":"Security teams are facing a newer form of shadow AI as approved enterprise applications increasingly gain the ability to run extensions, connect to outside services and follow instructions supplied by software repositories. An analysis published by The Hacker News on August 31 argues that the security problem is no longer\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Shadow AI Is Now Hiding Inside Sanctioned AI Tools","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6539,"url":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/","url_meta":{"origin":5850,"position":1},"title":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack","author":"Daniel Chinonso John","date":"August 15, 2026","format":false,"excerpt":"A new npm supply-chain attack has compromised hundreds of JavaScript packages and turned stolen developer credentials into a mechanism for spreading the malware to additional projects. Researchers tracking the campaign have identified 444 unique npm packages and 2,212 compromised versions in one August 4 investigation snapshot, while separate researchers recorded\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":6308,"url":"https:\/\/areeblog.com\/secure-coding-practices-in-the-ai-era\/","url_meta":{"origin":5850,"position":2},"title":"Secure Coding Practices in the AI Era","author":"Samuel Ogori","date":"July 12, 2026","format":false,"excerpt":"Writing code has never been easier. Ironically, keeping that code secure has never demanded more attention. AI coding assistants can generate hundreds of lines of functional code in seconds, recommend libraries, explain unfamiliar frameworks, and even fix bugs. That speed is undeniably useful. But speed also has a way of\u2026","rel":"","context":"In &quot;Artificial Intelligence&quot;","block_context":{"text":"Artificial Intelligence","link":"https:\/\/areeblog.com\/category\/artificial-intelligence\/"},"img":{"alt_text":"Secure Coding Practices in the AI Era","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0006.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0006.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0006.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0006.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0006.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6302,"url":"https:\/\/areeblog.com\/how-hallucinated-packages-become-an-attack-vector\/","url_meta":{"origin":5850,"position":3},"title":"How Hallucinated Packages Become an Attack Vector","author":"Daniel Chinonso John","date":"July 11, 2026","format":false,"excerpt":"Trust is becoming one of the most valuable\u2014and most dangerous\u2014currencies in software development. Every time an AI coding assistant suggests a library, most developers assume it exists. That assumption is increasingly being weaponized, not by breaking into software repositories, but by waiting for AI to imagine a package that has\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"How Hallucinated Packages Become an Attack Vector","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":951,"url":"https:\/\/areeblog.com\/phishing-vs-spear-phishing-how-to-tell-the-difference-and-protect-yourself\/","url_meta":{"origin":5850,"position":4},"title":"Phishing vs. Spear Phishing: How to Tell the Difference and Protect Yourself","author":"Daniel Chinonso John","date":"May 14, 2025","format":false,"excerpt":"Phishing and spear phishing are sneaky online tricks, not just minor tech problems. They're planned scams that try to fool us by playing on our trust and sense of urgency in how we talk to each other every day. We need to understand how these scams target our human nature\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"Phishing vs. Spear Phishing: How to Tell the Difference and Protect Yourself","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/05\/phishing-vs-spear-phishing-Aree-Blog.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/05\/phishing-vs-spear-phishing-Aree-Blog.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/05\/phishing-vs-spear-phishing-Aree-Blog.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/05\/phishing-vs-spear-phishing-Aree-Blog.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/05\/phishing-vs-spear-phishing-Aree-Blog.jpg?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/05\/phishing-vs-spear-phishing-Aree-Blog.jpg?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":6720,"url":"https:\/\/areeblog.com\/ai-coding-agents-found-running-malicious-git-commands-before-user-approval\/","url_meta":{"origin":5850,"position":5},"title":"AI Coding Agents Found Running Malicious Git Commands Before User Approval","author":"Daniel Chinonso John","date":"September 1, 2026","format":false,"excerpt":"Security researchers at Manifold Security have identified six high-severity security findings across five AI coding agents that can allow attacker-controlled code to run while the agents gather repository information. The research, published September 1, 2026, covers Claude Code, Qwen Code, Goose, Grok Build and Hermes Agent. Manifold said two of\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"AI Coding Agents Found Running Malicious Git Commands Before User Approval","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_featured_media_url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg","_links":{"self":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/5850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/comments?post=5850"}],"version-history":[{"count":0,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/5850\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media\/5851"}],"wp:attachment":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media?parent=5850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/categories?post=5850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/tags?post=5850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}