Malicious VSCode extension in Cursor IDE led to $500K crypto theft

Malicious VSCode extension in Cursor IDE led to 0K crypto theft

A malicious extension disguised as a legitimate Solidity language tool infected devices, stealing cryptocurrency and installing remote access tools. This incident highlights the risks of open-source package repositories being exploited by threat actors. #QuasarRAT #OpenVSX

Keypoints

  • Cybercriminals used a fake extension to infect developers’ devices and steal cryptocurrency.
  • The malicious extension impersonated a legitimate syntax highlighting tool for Ethereum smart contracts.
  • Remote PowerShell scripts installed ScreenConnect, granting full remote access to hackers.
  • Malicious payloads included Quasar RAT and credential-stealing malware like PureLogs.
  • Inflated download counts and gaming algorithms were used to promote malicious extensions on open repositories.

Read More: https://www.bleepingcomputer.com/news/security/malicious-vscode-extension-in-cursor-ide-led-to-500k-crypto-theft/