TigerJack Hackers Target Developer Marketplaces with 11 Malicious VS Code Extensions
A cybersecurity incident has affected over 17,000 developers through the use of malicious Visual Studio Code extensions. These extensions, distributed by a threat actor identified as TigerJack, have been designed to steal source code, mine…
A cybersecurity incident has affected over 17,000 developers through the use of malicious Visual Studio Code extensions. These extensions, distributed by a threat actor identified as TigerJack, have been designed to steal source code, mine cryptocurrency, and create backdoors for remote system access.
Operating under the publisher accounts such as ab-498 and 498-00, TigerJack has deployed at least 11 malicious extensions. The most notable among these are "C++ Playground" and "HTTP Format". Although these extensions have been removed from Microsoft's VS Code marketplace, they remain available on the OpenVSX marketplace, impacting developers using alternative IDEs.
The extensions perform as advertised, making them difficult to detect. "C++ Playground" offers real-time code compilation and formatting, while "HTTP Format" provides HTTP file formatting. However, both contain hidden functionalities that compromise user systems.
The "C++ Playground" extension logs keystrokes and transmits source code to external endpoints. The "HTTP Format" extension covertly utilizes infected machines for cryptocurrency mining.
A cybersecurity incident has affected over 17,000 developers through the use of malicious Visual Studio Code extensions.
Three extensions within the 498 publisher account possess remote code execution capabilities. These create persistent backdoors, allowing for command execution every 20 minutes. This functionality enables dynamic payload deployment, transforming the operation into an open-door attack platform.
The TigerJack campaign exposes significant weaknesses in the security protocols of developer marketplaces. Despite Microsoft's removal of some extensions, no notifications were provided to affected developers. Furthermore, these malicious extensions remain active on OpenVSX, demonstrating the fragmented nature of security efforts across platforms.
For developers, this incident highlights the need for robust security measures when evaluating and using third-party extensions. It also underscores the importance of coordinated security efforts across different marketplaces to prevent similar threats in the future.
Based on reporting by GBHackers.
