MaliciousCorgi: The VSCode Attack Hiding in Plain Sight - 1.5 Million Installs Affected
Two VSCode extensions with 1.5 million installs are stealing source code right now, not last month. Researchers published their findings on January 22. Three days later, both extensions are still live on Microsoftβs official marketplace. Still collecting downloads. Still harvesting files. π§
The extensions are ChatGPT - δΈζη with 1.34 million installs and ChatMoss with 150,000 installs. Both marketed as AI coding assistants. Both work as advertised. Both contain identical spyware that sends everything to servers in China. Researchers named the campaign MaliciousCorgi.