Listen to this Post
Cybersecurity researchers have recently uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace that were designed to deliver ransomware still under development. These extensions, identified as “ahban.shiba” and “ahban.cychelloworld,” were swiftly removed by the marketplace maintainers once the threat was discovered.
Both extensions featured code that invoked a PowerShell command, which fetched a script from a command-and-control (C2) server to execute a suspicious payload. This payload is suspected to be an early-stage ransomware, which encrypts files in a folder named “testShiba” on a victim’s Windows desktop. The encrypted files are then accompanied by a message demanding 1 ShibaCoin to recover them, although the message lacks further details like a cryptocurrency wallet address. This indicates that the malware is still in development.
The discovery of these extensions follows previous alerts regarding other malicious tools in developer marketplaces. Just months earlier, a series of malicious extensions impersonating popular software like Zoom were flagged for containing a secondary payload that could be downloaded from a remote server. Additionally, a Maven package pretending to be an OAuth library was also found to be collecting and exfiltrating sensitive credentials, evading detection through time-based triggers.
Summary: A Wake-Up Call for Developers
Security researchers recently uncovered two dangerous extensions in the VSCode Marketplace—”ahban.shiba” and “ahban.cychelloworld”—designed to deploy ransomware in its early stage of development. These extensions used PowerShell commands to fetch a script from a C2 server, encrypt files in a specific folder on the victim’s desktop, and display a ransom message demanding ShibaCoin for file recovery. The fact that these extensions were swiftly removed by VSCode’s marketplace maintainers highlights the ongoing risks in developer tools.
These findings come after previous discoveries of malicious extensions and packages in developer marketplaces, such as those mimicking Zoom or OAuth libraries. The malware’s underdevelopment status was evidenced by the lack of details or functional cryptocurrency wallet addresses in the ransom message, indicating the attackers were still refining their tools.
The presence of such malicious tools within trusted platforms like VSCode and Maven speaks to the vulnerabilities that persist in software development environments, where malicious actors use methods like typosquatting to target unsuspecting developers. This latest discovery is a reminder of the growing risks developers face from increasingly sophisticated supply chain attacks.
What Undercode Say:
The presence of malicious extensions in the Visual Studio Code Marketplace is a worrying trend, especially given the growing reliance on software marketplaces and integrated development environments (IDEs) like VSCode for building and deploying applications. Developers use these platforms for their efficiency, but it also makes them targets for attackers looking to exploit the ecosystem for malicious purposes.
Ransomware in the early stages of development could be an indication of broader, more dangerous malware campaigns in the making. While these specific extensions only encrypted files within a designated folder and lacked further instruction on how to pay the ransom, this could be the foundation for more sophisticated versions of the ransomware. It’s important to note that the lack of further wallet details might not just be a sign of underdevelopment—it could also point to attackers trying to test and refine their attack methods before a larger deployment.
The increasingly complex nature of these attacks also raises the concern of “supply chain attacks,” where an attacker targets trusted platforms or widely used libraries to spread malware. These attackers often employ tactics such as typosquatting, where they create almost identical names to legitimate tools, fooling developers into downloading malicious code unknowingly. In this case, the malicious Maven package impersonated an OAuth library and harvested sensitive data in a stealthy manner, triggering the exfiltration process based on a time-based mechanism to avoid detection.
What’s most alarming is the persistence of these types of threats in widely-used, trusted development environments. Developers, who often prioritize convenience and trust in these platforms, may overlook the possibility of malicious code entering their workflow. The targeted exploitation of these environments suggests attackers are adapting, continuously improving their techniques, and specifically focusing on tools that developers rely on to build their applications.
This situation highlights the importance of vigilance within the development community. Developers need to verify the authenticity of the tools they use, especially when dealing with packages and extensions from external sources. Security measures like regular security audits, code scanning, and awareness of the latest cybersecurity threats are essential steps in mitigating risks.
Furthermore, with the rise of ransomware and other forms of malware that specifically target developers, there’s a growing need for cybersecurity measures at the infrastructure level. Software repositories, marketplaces, and development tools must continue to improve their defenses, ensuring that they are not inadvertently becoming vectors for cyber-attacks. Additionally, developers need to adopt a mindset of security-first, integrating security practices into their development lifecycle and not assuming that popular platforms are inherently secure.
Fact Checker Results
- The malicious extensions “ahban.shiba” and “ahban.cychelloworld” were identified and removed from the VSCode Marketplace.
- The extensions executed a PowerShell command to download a suspected ransomware payload.
- The ransomware was still under development, encrypting files in a specific folder and displaying a ransom message demanding payment in ShibaCoin, without further instructions.
References:
Reported By: https://thehackernews.com/2025/03/vscode-marketplace-removes-two.html
Extra Source Hub:
https://www.facebook.com
Wikipedia
Undercode AI
Image Source:
Pexels
Undercode AI DI v2





