Listen to this Post

Introduction
A startling vulnerability has been discovered in the Visual Studio Code (VS Code) Marketplace, allowing cybercriminals to exploit removed extensions’ names. This loophole enables threat actors to push malicious code under seemingly familiar extension names, putting developers and organizations at risk of ransomware attacks and sensitive data theft. Recent research by ReversingLabs has shed light on this growing threat within software supply chains.
Malicious Extension Discovery
Cybersecurity researchers identified a dangerous extension called “ahbanC.shiba” that mirrored earlier flagged extensions, ahban.shiba and ahban.cychelloworld. Each of these extensions acts as a downloader for a PowerShell payload, encrypting files in a folder named “testShiba” on victims’ Windows desktops. The malware then demands a Shiba Inu token ransom, showing that attackers are refining their tactics to monetize ransomware attacks.
How the Loophole Works
Typically, every VS Code extension must have a unique identifier combining the publisher’s name and the extension’s name. However, ReversingLabs discovered that once an extension is removed, its name can be reused by other publishers. This loophole violates official documentation requiring unique extension names and opens a pathway for malicious actors to impersonate legitimate extensions.
Comparison with PyPI Repository
This behavior mirrors earlier findings in the Python Package Index (PyPI), where deleted package names could also be reused unless flagged as malicious. Unlike PyPI, VS Code currently lacks safeguards to prevent the reuse of names from previously harmful extensions, leaving the marketplace vulnerable.
Threat Actors’ Strategies
Leaked Black Basta chat logs indicate a strategic push by attackers to poison open-source repositories with ransomware and malware libraries. By leveraging these loopholes, threat actors increase the chances of unsuspecting developers installing compromised extensions, emphasizing the urgent need for proactive monitoring and secure development practices.
Wider Software Supply Chain Risks
The VS Code vulnerability comes amid the discovery of eight malicious npm packages capable of stealing sensitive user data such as passwords, crypto wallets, and cookies. These packages, developed by users “ruer” and “npjun,” used 70 layers of obfuscated code to deploy Python payloads for data exfiltration, highlighting sophisticated, multi-layered attacks in open-source ecosystems.
Expert Insights
Security researchers stress that open-source repositories are increasingly exploited as entry points for cyberattacks. Threat actors employ typosquatting, masquerading, and obfuscation techniques to bypass conventional security measures. Organizations must adopt continuous automated scanning and maintain a single source of truth for all software components to mitigate these risks effectively.
What Undercode Say: In-Depth Analysis
The discovery of this VS Code loophole exposes systemic weaknesses in software supply chains. First, the reuse of deleted extension names undermines trust in open-source repositories and allows threat actors to masquerade as reputable developers. This could lead to an increase in supply chain attacks, where malicious code infiltrates legitimate development projects.
Second, the similarity between extensions like ahban.shiba and ahbanC.shiba demonstrates that attackers are actively evolving malware tactics. By slightly altering extension names while retaining malicious functionality, attackers exploit human oversight, increasing the chances of installation.
Third, parallels with PyPI highlight a broader industry problem: repositories often lack stringent protections against the reuse of names from removed malicious packages. The absence of such safeguards in VS Code leaves it vulnerable to recurring attacks unless policy changes are implemented.
Fourth, multi-layer obfuscation, as seen in npm malware packages, indicates a trend toward sophisticated attacks designed to evade detection. Attackers can encrypt payloads and deploy multi-step infection chains, requiring advanced monitoring and endpoint detection systems to neutralize threats.
Fifth, ransomware payloads like those in the “testShiba” folder suggest an evolving monetization strategy for cybercriminals. By demanding cryptocurrency payments, attackers exploit anonymity and complicate law enforcement tracking, making ransomware a persistent threat.
Sixth, the leaked Black Basta logs illustrate a collaborative and organized approach to poisoning open-source repositories. Threat actors are not only creating malware but also strategizing deployment, showcasing the industrialization of cybercrime.
Seventh, organizations relying on open-source extensions must adopt strict vetting processes, automated security scans, and awareness programs to reduce human error. Relying solely on marketplace checks is no longer sufficient.
Eighth, the identification of malicious npm packages stealing sensitive data reinforces the need for end-to-end supply chain visibility. Companies must map all dependencies, monitor updates, and implement real-time threat intelligence to stay ahead of attackers.
Ninth, security researchers recommend integrating risk scoring systems for extensions and packages, which can help developers quickly identify potential threats. Coupled with continuous monitoring, this approach can significantly reduce exposure to malicious code.
Tenth, these developments underscore a broader cybersecurity lesson: open-source ecosystems are double-edged swords. While they fuel innovation, they also present complex vulnerabilities that require proactive and layered defenses.
Eleventh, regulators and platform maintainers must revisit policies, especially regarding the reuse of deleted extension names. Creating exceptions for previously malicious extensions could prevent attackers from exploiting these gaps in the future.
Twelfth, the VS Code case illustrates how attackers leverage trust and familiarity to gain access to sensitive systems, showing that even a single loophole can have far-reaching consequences.
Thirteenth, training developers on secure coding practices and the dangers of installing unverified extensions is now essential for reducing the success rate of such attacks.
Fourteenth, the malicious extensions highlight that even widely used software marketplaces are not immune to supply chain threats, emphasizing the importance of continuous cybersecurity audits.
Fifteenth, industry-wide collaboration between cybersecurity firms, open-source platforms, and law enforcement can help detect, block, and remediate these threats faster.
Sixteenth, as attackers evolve, the implementation of AI-powered monitoring tools for behavioral analysis and anomaly detection becomes increasingly critical to protect open-source ecosystems.
Seventeenth, organizations must prepare for ransomware contingency plans as supply chain attacks become more targeted and financially motivated.
Eighteenth, end-users need better awareness about extension authenticity, digital signatures, and publisher credibility to avoid falling victim to these sophisticated attacks.
Nineteenth, the incident reiterates the importance of patch management and timely updates, which can prevent the exploitation of vulnerabilities in development environments.
Twentieth, the VS Code loophole case is a wake-up call for cross-platform vigilance, as similar patterns may exist in other software marketplaces beyond Python and JavaScript ecosystems.
Twenty-first, investing in threat intelligence sharing across industries will enhance resilience and reduce attack surface.
Twenty-second, awareness campaigns about typosquatting, masquerading, and malicious extensions can significantly improve developer security hygiene.
Twenty-third, the threat of cryptocurrency-based ransom highlights the need for financial monitoring and tracking solutions to counter illicit transactions.
Twenty-fourth, enterprises must adopt a zero-trust approach to software dependencies, treating all external packages as potentially risky.
Twenty-fifth, creating internal registries with vetted extensions can prevent accidental exposure to malicious marketplace packages.
Twenty-sixth, ongoing research by firms like ReversingLabs is critical to identifying evolving attack patterns and developing timely mitigation strategies.
Twenty-seventh, collaboration with security researchers can facilitate rapid takedown of malicious packages before widespread damage occurs.
Twenty-eighth, the incident underscores the need for robust logging and monitoring to detect unusual activities in software supply chains.
Twenty-ninth, digital forensics and malware analysis are now indispensable tools for organizations to understand attack mechanisms and strengthen defenses.
Thirtieth, proactive and layered defenses, combined with strong developer education and marketplace policies, remain the most effective approach to mitigate threats in the evolving open-source ecosystem.
✅ Fact Checker Results
Reuse of deleted VS Code extension names is a confirmed loophole. ✅
Malicious extensions like “ahbanC.shiba” can deliver ransomware and crypto ransom demands. ✅
No current VS Code restriction prevents reuse of previously malicious extension names. ✅
🔮 Prediction
Given the rising sophistication of supply chain attacks, it is likely that VS Code and other software marketplaces will soon introduce stricter controls on extension name reuse. Cybercriminals may shift toward exploiting other overlooked vulnerabilities in open-source ecosystems, including dependency chains and automated package updates, increasing the need for proactive monitoring and AI-driven threat detection.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.discord.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




