Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Compromising Developers with Malicious VS Code, Cursor AI Extensions

Developer tools, widely used by programmers globally, are increasingly being targeted by attackers aiming to compromise entire organizations. Visual Studio Code and AI-powered Integrated Development Environments (IDEs) like Cursor AI, particularly when…

Developer tools, widely used by programmers globally, are increasingly being targeted by attackers aiming to compromise entire organizations. Visual Studio Code and AI-powered Integrated Development Environments (IDEs) like Cursor AI, particularly when integrated with their extension marketplaces, present significant vulnerabilities within the software supply chain.

Developers often have access to sensitive credentials, source code repositories, and production systems, making them valuable targets for sophisticated threat actors. A new security issue has emerged, highlighting the ease with which malicious extensions can be published to these marketplaces.

This attack vector takes advantage of the trust developers place in their development environments, bypassing various protection layers designed to secure these platforms. By masquerading harmful code as legitimate tools, attackers can gain persistent access to developer systems without triggering typical security alerts.

A cybersecurity engineer, Mazin Ahmed, identified and documented the methods by which attackers successfully publish backdoors through these extension marketplaces. Ahmed's research demonstrated that a malicious Python linter extension, intentionally misspelled as Piithon-linter to avoid immediate detection, passed through Microsoft's security checks and became available on the VS Code Marketplace.

Developer tools, widely used by programmers globally, are increasingly being targeted by attackers aiming to compromise entire organizations.
Olivia Harper · Thehackingpost

This capability allowed attackers to exfiltrate environment variables containing sensitive credentials and deploy remote access tools upon installation. A particularly concerning aspect of this attack is how the malware maintains persistence and evades detection systems.

Upon launching VS Code, the malicious extension automatically executes without requiring user interaction, utilizing activation events specified in the extension’s configuration. Initially, the extension scans for running antivirus or endpoint detection solutions, halting execution if security software is detected. If the system appears safe, the extension proceeds to harvest environment variables and deploy a Merlin command-and-control agent, granting attackers complete remote access .

The extension is capable of determining the operating system at runtime, enabling it to execute the appropriate payload for Windows, macOS, or Linux systems. This research uncovered significant gaps in security screening processes.

Advertisement

Microsoft’s sandbox analysis, which is intended to test extensions in a controlled environment, was circumvented through geofencing techniques that detected when code was executed within Microsoft’s United States-based testing infrastructure.

OpenVSX, the marketplace powering Cursor AI and other AI-powered IDEs, performs minimal security verification, relying solely on user reporting and agreement terms. These findings underscore a critical issue: major supply chain compromises could originate from the editors and developers that are trusted and used daily. Without enhanced security controls and verification mechanisms, these essential development tools remain vulnerable to coordinated attacks.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories