#TigerJack
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
thehackernews.com/2025/10/over...
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
Wiz exposed 550 leaked secrets in VS Code extensions, as TigerJack exploits marketplaces with malware.
thehackernews.com
October 18, 2025 at 3:07 PM
Alert: Malicious VS Code extensions by TigerJack have compromised thousands of developers. Stay vigilant and review your extensions. #CyberSecurity #VSCode #DeveloperSafety Link: thedailytechfeed.com/tigerjacks-m...
October 16, 2025 at 9:41 AM
Malicious crypto-stealing VSCode extensions resurface on OpenVSX 🔥🕵️‍♂️

Threat actor TigerJack is targeting developers with malicious extensions published on #Microsoft's VSCode marketplace and OpenVSX registry to steal #cryptocurrency and plant #backdoors 💥

www.bleepingcomputer.com/news/securit...
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
A threat actor called TigerJack is constantly targeting developers with malicious extensions published on Microsoft's Visual Code (VSCode) marketplace and OpenVSX registry to steal cryptocurrency and ...
www.bleepingcomputer.com
October 15, 2025 at 1:21 PM
Plus de 100 extensions #VSCode exposent les développeurs à des risques cachés dans la chaîne d’approvisionnement. Des jetons d’accès ont été divulgués, permettant à des pirates de diffuser des mises à jour malveillantes. ⚠️🔐 #CyberSecurity #IA #InnovationIA https://kntn.ly/259b5bd1
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
Wiz exposed 550 leaked secrets in VS Code extensions, as TigerJack exploits marketplaces with malware.
thehackernews.com
October 16, 2025 at 4:00 PM
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks thehackernews.com/2025/10/over...
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
Wiz exposed 550 leaked secrets in VS Code extensions, as TigerJack exploits marketplaces with malware.
thehackernews.com
October 16, 2025 at 8:12 PM
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
A threat actor called TigerJack is constantly targeting developers with malicious extensions published on Microsoft's Visual Code (VSCode) marketplace and OpenVSX registry to steal cryptocurrency and plant backdoors.
www.bleepingcomputer.com
October 14, 2025 at 10:47 PM
TigerJack. l' unico dei quattro ad avere solo un nome inglese é proprio l' indiano.
July 23, 2026 at 3:53 PM
Notícia da BleepingComputer

"Malicious crypto-stealing VSCode extensions resurface on OpenVSX" #bolhasec
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
A threat actor called TigerJack is constantly targeting developers with malicious extensions published on Microsoft's Visual Code (VSCode) marketplace and OpenVSX registry to steal cryptocurrency and ...
www.bleepingcomputer.com
October 24, 2025 at 2:30 PM
17K+ developers hit by TigerJack malware via malicious VSCode extensions.

Code theft, crypto mining & backdoors - a supply chain threat hiding in plain sight.

#CyberSecurity #VSCode #Malware #Infosec
October 15, 2025 at 2:15 PM
A threat actor known as TigerJack has infiltrated developer marketplaces, distributing at least 11 malicious Visual Studio Code extensions that have infected thousands of unsuspecting developers worldwide.
https://cybersecuritynews.com/tigerjack-hacks-infiltrated-developer-marketplaces/
October 15, 2025 at 12:58 PM
TigerJack Hacks Infiltrated Developer Marketplaces with 11 Malicious VS Code Extensions
TigerJack Hacks Infiltrated Developer Marketplaces with 11 Malicious VS Code Extensions
cybersecuritynews.com
October 15, 2025 at 12:07 PM
TigerJack’s malicious VSCode extensions mine, steal, and stay hidden
In a new disclosure, security researchers revealed that a threat actor group called TigerJack has been publishing malicious extensions on Microsoft’s Visual Studio Code (VSCode) Marketplace and the OpenVSX registry to steal source code, plant cryptominers, and maintain remote access. According to Koi Security’s findings, two of the campaign’s popular extensions – “C++ Payground” and “HTTP Format” – were removed after accumulating over 17,000 downloads, but the operation continues through re-uploads under fresh accounts. “These extensions remain fully operational in the OpenVSX marketplace (used by Cursor, Windsurf, and other VS Code-compatible IDEs), continuing to steal code and mine cryptocurrency months after their removal from Microsoft’s platform,” Koi researchers said in a blog post. Researchers have flagged it to be a coordinated campaign spanning at least 11 extensions across 3 different publisher accounts (ab-498,498 and 498-00). ## Trojanized extensions built for persistence Koi’s analysis shows that each malicious extension serves a distinct role in TigerJack’s campaign. One version quietly uploads a developer’s source code to external endpoints, another uses local resources for cryptomining, and the most “sophisticated” variant can execute JavaScript remotely without needing fresh updates for expanding or changing functionalities. Aditya Sood, VP of Security Engineering and AI Strategy at Aryaka, thinks the last capability is particularly dangerous, allowing TigerJack to push payloads such as credential stealers, ransomware, or API-harvesting scripts at will, opening the door to long-term supply chain compromise. Because the core payload execution is often handled via dynamic, remote JavaScript, rather than by shipping updated binaries, the extension’s visible version remains unchanged, making detection by static scanners or vetting systems far more difficult, researchers added. In some cases, the malicious packaging is cleverly designed with the extensions masquerading as legitimate or popular tools that attackers even silently installed (on top of the malicious functionality) to avoid suspicion. In essence, the campaign blends two capabilities, cryptomining and persistent backdoor control. In the mining variants, the extension deploys a miner that quietly consumes CPU (and sometimes GPU) cycles on developer machines, abusing the host’s processing power into illicit cryptocurrency generation. ## Coordinated multi-account operation Koi researchers found 11 extensions across multiple accounts, making it a coordinated operation. “This multi-account strategy provides redundancy when one account gets flagged, creates the illusion of independent developers, and demonstrates professional-level social engineering: GitHub repositories for credibility, consistent branding across extensions, detailed feature lists, professional marketplace presentations, and strategic naming that mimics legitimate tools (cppformat, pythonformat, httpformat),” the researchers said. The analysis traced the malicious GitHub accounts back to a Facebook profile under the name “Zubaer Ahmed,” pointing to a likely operational slip that exposed the attacker’s real identity. The profile has since been taken down. For developers and organizations relying heavily on VSCode or OpenVSX, the extensions could compromise not just a codebase but entire build environments or deployment pipelines, Sood noted. Compromised extensions can silently exfiltrate or tamper with source code that later moves into production, effectively turning VSCode into a vector for software supply-chain attacks. In collaborative environments, a single infected deployment could compromise shared repositories or inject backdoors into dependencies. Koi researchers emphasized that TigerJack’s re-emergence reveals a deeper weakness in the extension ecosystem, with developer tools still relying on reputation and user ratings, rather than code auditing or signed binaries. “OpenVSX and other alternative marketplaces appear to have virtually no security detection mechanisms in place,” they said. “While Microsoft eventually identifies threats after months of damage, these platforms operate with minimal or no malware scanning whatsoever.” Individuals using either of the impacted platforms should vet their extensions thoroughly and only download packages from reputable sources, Sood added. “Additionally, users should implement security measures that can raise alarms about potential vulnerabilities so users have the opportunity to close them before they’re exploited.”
www.csoonline.com
October 16, 2025 at 10:21 AM
📢 TigerJack diffuse 11 extensions VS Code malveillantes : vol de code, cryptominage et backdoors
📝 Selon Koi Security (billet de recherche), le grou…
https://cyberveille.ch/posts/2025-10-14-tigerjack-diffuse-11-extensions-vs-code-malveillantes-vol-de-code-cryptominage-et-backdoors/ #IOC #Cyberveille
October 14, 2025 at 10:00 PM
Malicious crypto-stealing VSCode extensions resurface on OpenVSX

A threat actor called TigerJack is constantly targeting developers with malicious extensions published on Microsoft's Visual Code (VSCode) marketplace and OpenVSX registry to steal cryptocurrency and pla…

#hackernews #microsoft #news
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
A threat actor called TigerJack is constantly targeting developers with malicious extensions published on Microsoft's Visual Code (VSCode) marketplace and OpenVSX registry to steal cryptocurrency and plant backdoors. [...]
www.bleepingcomputer.com
October 15, 2025 at 10:04 PM
The Hidden Cyber Ambush: How 11 Malicious VS Code Extensions Infiltrated 17,000 Developers

The Silent Breach in a Trusted Ecosystem In a shocking revelation that rippled across the global developer community, a cyber group known as TigerJack managed to slip 11 malicious Visual Studio Code (VS…
The Hidden Cyber Ambush: How 11 Malicious VS Code Extensions Infiltrated 17,000 Developers
The Silent Breach in a Trusted Ecosystem In a shocking revelation that rippled across the global developer community, a cyber group known as TigerJack managed to slip 11 malicious Visual Studio Code (VS Code) extensions into the marketplace. These extensions weren’t just faulty code—they were a meticulously engineered weapon, designed to steal C++ source files, mine cryptocurrencies, and open remote backdoors into developers’ systems.
undercodenews.com
October 27, 2025 at 4:25 AM
Malicious VSCode Extensions Target Developers and Crypto Assets

A recent cybersecurity alert has uncovered a series of malicious Visual Studio Code (VSCode) extensions distributed by the threat actor known as TigerJack. These deceptive extensions, masquerading as legitimate tools like "C++…
Malicious VSCode Extensions Target Developers and Crypto Assets
A recent cybersecurity alert has uncovered a series of malicious Visual Studio Code (VSCode) extensions distributed by the threat actor known as TigerJack. These deceptive extensions, masquerading as legitimate tools like "C++ Playground" and "HTTP Format," have been found on both the Microsoft Marketplace and the OpenVSX registry. Their primary objective is to steal cryptocurrency and install backdoors on developers' systems.
undercodenews.com
October 14, 2025 at 11:45 PM
TigerJack Hacks infiltrated Developer Marketplaces with 11 Malicious VS Code Extensions:

cybersecuritynews.com/tigerjack-ha...
October 15, 2025 at 6:16 PM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Wednesday, October 15, 2025
TigerJack Hackers Target Developer Marketplaces with 11 Malicious VS Code Extensions
Sophisticated Threat Actor Compromises 17,000+ Developers Through Trojan Extensions That Steal Code and Mine Cryptocurrency.
gbhackers.com
October 15, 2025 at 10:26 PM
Your code editor is a loot box with root access.
550 secrets, 250k installs, and a backdoor that cosplays as a theme.
Update now—your next “productivity” patch might mine crypto in your dreams.
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
Wiz exposed 550 leaked secrets in VS Code extensions, as TigerJack exploits marketplaces with malware.
thehackernews.com
October 21, 2025 at 8:15 PM