Dubai Times

Live, Love, Leverage – Ya Habibi!
Monday, Aug 17, 2026

Hackers Are Hiding Malware in Open-Source Tools and IDE Extensions

The common belief that “open source is safe because everyone can inspect the code” is misleading. In reality, most open-source projects include add-ons and components that are not open source at all — and these hidden parts can easily contain spyware, malware, and viruses. Once installed, they can take over both the user’s computer and the servers running the so-called open-source code, giving hackers full control to do whatever they want.

A newly uncovered cyberattack—one of the most sophisticated developer-focused campaigns seen in recent years—is weaponizing the daily workflow of software engineers. 

Security companies have revealed a malicious operation in which attackers insert stealthy malware into seemingly harmless extensions and open-source tools used by tens of thousands of developers worldwide. 

These extensions appear completely legitimate, yet silently exfiltrate highly sensitive data such as passwords, Wi-Fi access credentials, authentication tokens, clipboard contents, and even live screenshots taken directly from developers’ machines.


Compromised VS Code Extensions: “Bitcoin Black” and “Codo AI”

Two Visual Studio Code extensions were confirmed to contain embedded malicious components: the Bitcoin Black theme and an AI assistant tool called Codo AI. Both extensions looked fully legitimate on the marketplace and performed their advertised functions, which helped them evade suspicion and achieve wide adoption.

Once installed, the extensions deployed an additional malicious payload that continuously harvested data from infected devices. The threat actors were not content with collecting passwords alone. The malware captured real-time screenshots of developers’ screens—revealing source code, Slack discussions, credentials, internal documentation, and confidential project directories.

This level of visibility allows attackers to map entire workflows, understand sensitive architectures, and target organizations with precision.


The Attack Technique: DLL Hijacking as a Delivery Vehicle

The operation relied on an advanced method known as DLL hijacking, which abuses the way legitimate software loads system libraries.

The attackers downloaded a real, benign screenshot tool (Lightshot) onto the victim’s machine, pairing it with a malicious DLL that carried the same filename as the tool’s expected library. When Lightshot launched, it automatically loaded the attacker’s counterfeit DLL. This triggered the malware’s execution without raising suspicion.

Security researchers found that the malware collected:

  • Continuous screenshots and clipboard data

  • Wi-Fi passwords and saved wireless credentials

  • Browser cookies, authentication tokens, and active sessions (via Chrome and Edge in headless mode)

  • Information about installed software, running processes, and development tools

Koi Security reports that the attackers have been iterating and improving the operation, increasingly using “clean” and innocuous-looking scripts to blend in with normal developer activity.


The Campaign Is Spreading Beyond VS Code

While the first findings emerged in VS Code, similar malicious injections are now appearing across the broader open-source ecosystem:

  • npm and Go: Malware packages imitating the names of popular, trusted libraries

  • Rust: A library called finch-rust masqueraded as a scientific computation tool, but instead loaded an additional malware component called sha-rust

This reflects a direct attack on the software supply chain—the trust mechanism developers rely on when importing packages, extensions, or dependencies. By compromising tools that sit at the heart of software development, attackers gain privileged access to entire organizations.


Why This Threat Is So Dangerous

A single developer installing one benign-looking extension can unknowingly trigger a breach across the entire company:

  • Theft of core, proprietary source code

  • Takeover of GitHub and other cloud development accounts

  • Infection of CI/CD pipelines and build environments

  • Exposure of sensitive customer data, credentials, and internal architecture

Because development environments are privileged by design—holding secrets, tokens, SSH keys, and code—the blast radius of compromise is enormous.

Traditional static code scanning is insufficient for detecting these attacks. The extensions themselves often appear legitimate or include harmless code alongside hidden payloads. What is required is real-time behavioral monitoringcapable of flagging anomalous actions—such as a theme extension attempting to access stored passwords.


Recommended Security Measures for Developers and Organizations

To reduce exposure, cybersecurity firms recommend the following defensive steps:

  1. Enable multi-factor authentication on all development accounts, including GitHub, GitLab, cloud providers, and CI/CD tools.

  2. Verify the identity and reputation of extension publishers before installation.

  3. Avoid anonymous, poorly reviewed, or unknown plugins—even if they appear harmless.

  4. Adopt security tools that include behavioral detection, not only static scanning.

  5. Treat all AI-powered development tools with caution, especially those requesting elevated system permissions.

  6. Conduct regular audits of development environments, including browser sessions, secrets, stored tokens, and installed extensions.


This attack marks a turning point in developer-focused cybercrime. 

By targeting the very tools that developers rely on daily, attackers gain unprecedented access to the global software ecosystem. The findings underscore the urgent need for stronger supply-chain security, rigorous extension vetting, and behavioral monitoring to defend the world’s most sensitive development workflows.

Newsletter

Related Articles

0:00
0:00
Close
Cristiano Ronaldo and Georgina Rodríguez Sign Prenup Protecting Their Separate Fortunes
Google Launches Pixel 11 With Gemini AI at the Center of Its Hardware Strategy
Turkish Parliament Passes Landmark Bill Granting Conditional Amnesty to Disarmed PKK Members
Russia’s A7 Builds a State-Linked Payments Network Beyond Western Sanctions
Jorge Messi, Lionel Messi’s Father and Longtime Agent, Dies at 68
AI’s Next Bottleneck Is Power, Not Just Nvidia Chips
Meta Raises AI Spending Target to as Much as $145bn Despite Pressure Over Returns
Joe Biden’s Cancer Has Spread Beyond His Bones, Hunter Biden Says
Why 2027 Could Be a Strong Year for Stocks—and Why the Forecast Is Fragile
Why Markets May Look Quiet in August After Big Tech Earnings
Trump’s Top General Seeks an Exit Strategy From Iran War, Report Says
Brock Lesnar Retires From Wrestling, Closing a Career of Rare Athletic Range and Lasting Controversy
UFO: Pentagon Releases Video of Unidentified Object Tracked Over Middle East
Ukraine Tells Senate Republicans Its Drone War Offers a Blueprint for America
Weight-Loss Drug Boom Tests the Limits of Prescription Advertising Rules
UK Prosecutors Add 38 Charges Against Andrew and Tristan Tate
Saudi Arabia, Turkey and Pakistan Sign Mutual-Defence Pact
AI Is Remaking the US Economy, From GDP Growth to iPhone Prices
Modern Slavery Decisions Broaden the Al Fayed Inquiry’s Frame
FIFA’s Retreat Leaves a Larger Question Over Who Guards the Game
Finland Deploys Commercial-Scale Thermal Batteries Using Crushed Rock to Store Renewable Grid Energy
Valued at $109 Million: F-35B Fighter Jet Crashes in Southern California
US Says It Has Carried Out Heavy Strikes on Iran After Attempted Attacks on Its Forces
The AI User Nightmare: Private Claude Conversations Leaked to the Internet
UK: Former Football Association Leaders Call for World Cup Boycott Over FIFA Privatization Plan
Over 24 Hours in the Air: Qantas Airbus Completes Record-Breaking Test Flight
Arrest Warrant Issued in Lebanon for Tycoon Spotted Meeting Netanyahu in Washington
Trump says Israel ‘would not survive’ without US
Nvidia Reportedly Takes Vast Texas Data-Centre Lease to Underwrite AI Expansion
FIFA’s Private-Investment Plan for World Cup Rights Draws European Revolt
Apple Briefly Crosses Five Trillion Dollar Valuation as Investors Retreat From AI Bets
Following OpenAI's Cyberattack: 'Most Companies Still Do Not Understand What Is Coming'
OpenAI Sued After ChatGPT Allegedly Discouraged Emergency Care Before Near-Fatal Embolism
Miliband Sets Climate and International Law at Centre of UK Diplomacy
Pentagon Discloses Nearly 100 US Troop Injuries During Renewed Iran Fighting
Trump Readies New Tariffs as Temporary Global Levy Nears Expiry
High Prices Push Coffee Drinkers Toward Whole Beans and Home Brewing
Trump Draws Boos and Podium Scrutiny at Spain’s World Cup Triumph
Spain Defeats Argentina in Extra Time to Win Second World Cup
Turkey Explores S-400 Transfer to UAE in Bid to Rejoin F-35 Program
Singapore Considers Lower Taxes for Fund Managers as Hong Kong Intensifies Talent Contest
US Retaliates Against Iran After Two American Troops Killed in Jordan
Proposed U.S.-Saudi Nuclear Pact Could Permit Limited Uranium Enrichment Under International Safeguards
Netherlands Declares Water Shortage Emergency After Drought Pushes Rivers to Historic Lows
Why Kentucky Fried Chicken Became KFC—and Why the False Explanations Persist
Iran Claims It Destroyed Bahrain’s Main Artificial Intelligence Center in Missile and Drone Strike
Ukrainian Drones Strike Wildberries Warehouses Deep Inside Russia
Reported CIA Mission Helped Clear the UAE’s Path to Advanced US AI Chips
Artificial Intelligence Capital Fuels Markets While Governments and Regulators Face Mounting Strategic Tests
China’s Moonshot’s Kimi K3 Narrows the Gap With Anthropic Through Scale, Openness and Lower Cost
×