Cryptominer Chaos: Malicious VSCode Extensions Mine Your Crypto and Your Trust
Beware of cryptomining imposters! Nine VSCode extensions on Microsoft’s Marketplace are sneaking in XMRig miners. With over 300,000 installs, these sneaky add-ons pretend to be legit tools while secretly mining Ethereum and Monero. If you’ve installed them, it’s time to clean house!

Hot Take:
Looks like some sneaky extensions have made their way onto the VSCode Marketplace, and they’re not just trying to help you code. Instead, they’re giving your computer a workout by mining cryptocurrency in the background! Who knew your trusty code editor could moonlight as a financial advisor?
Key Points:
- Nine malicious VSCode extensions are posing as legitimate tools but secretly mine cryptocurrency.
- The extensions have amassed over 300,000 installs, possibly inflated to gain credibility.
- Extensions execute a PowerShell script to install the XMRig cryptominer.
- Malicious extensions perform various stealthy actions like disabling defenses and elevating privileges.
- Users are advised to remove these extensions and clean up any installed malware.
Already a member? Log in here