Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

TigerJack Hackers Target Developer Marketplaces with 11 Malicious VS Code Extensions

A cybersecurity incident has affected over 17,000 developers through the use of malicious Visual Studio Code extensions. These extensions, distributed by a threat actor identified as TigerJack, have been designed to steal source code, mine…

A cybersecurity incident has affected over 17,000 developers through the use of malicious Visual Studio Code extensions. These extensions, distributed by a threat actor identified as TigerJack, have been designed to steal source code, mine cryptocurrency, and create backdoors for remote system access.

Operating under the publisher accounts such as ab-498 and 498-00, TigerJack has deployed at least 11 malicious extensions. The most notable among these are "C++ Playground" and "HTTP Format". Although these extensions have been removed from Microsoft's VS Code marketplace, they remain available on the OpenVSX marketplace, impacting developers using alternative IDEs.

The extensions perform as advertised, making them difficult to detect. "C++ Playground" offers real-time code compilation and formatting, while "HTTP Format" provides HTTP file formatting. However, both contain hidden functionalities that compromise user systems.

The "C++ Playground" extension logs keystrokes and transmits source code to external endpoints. The "HTTP Format" extension covertly utilizes infected machines for cryptocurrency mining.

A cybersecurity incident has affected over 17,000 developers through the use of malicious Visual Studio Code extensions.
Charles Nolan · Thehackingpost

Three extensions within the 498 publisher account possess remote code execution capabilities. These create persistent backdoors, allowing for command execution every 20 minutes. This functionality enables dynamic payload deployment, transforming the operation into an open-door attack platform.

The TigerJack campaign exposes significant weaknesses in the security protocols of developer marketplaces. Despite Microsoft's removal of some extensions, no notifications were provided to affected developers. Furthermore, these malicious extensions remain active on OpenVSX, demonstrating the fragmented nature of security efforts across platforms.

Advertisement

For developers, this incident highlights the need for robust security measures when evaluating and using third-party extensions. It also underscores the importance of coordinated security efforts across different marketplaces to prevent similar threats in the future.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories