• News/
  • https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/

Malicious VSCode extensions infect Windows with cryptominers

BleepingComputer
·
Bill Toulas
·
Published Apr 7, 2025
·
Updated

A set of ten VSCode extensions on Microsoft's Visual Studio Code Marketplace pose as legitimate development tools while infecting users with the XMRig cryptominer for Monero. Microsoft VSCode is a popular code editor that allows users to install extensions to extend the program's functionality. These extensions can be downloaded from Microsoft's VSCode Marketplace, an online hub for developers to find and install add-ons. ExtensionTotal researcher Yuval Ronen has uncovered ten VSCode extensions published on Microsoft's portal on April 4, 2025. The package names are: At the time of publishing this article, the marketplace shows that the extensions amassed over 300,000 installs since April 4. However, after publishing the article Yuval Ronen added another extension with close to 500,000 installations. These numbers are likely artificially inflated to give the extensions a sense of legitimacy and popularity to entice others to install them. ExtensionTotal says it reported the malicious extensions to Microsoft, but they are still available at the time of writing. When installed and activated, the malicious extensions fetch a PowerShell script from an external source at 'https://asdf11[.]xyz/' and execute it. When finished, it also installs the legitimate extension it is impersonating, so the infected user does not become suspicious. The malicious PowerShell script performs multiple functions, like disabling defenses, establishing persistence, escalating privileges, and eventuall...

Read full article

Affected Software

3 affected components
Microsoft Visual Studio Code
Microsoft VSCode extensions
Microsoft Visual Studio Code
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how malicious VSCode extensions are infecting Windows machines with cryptominers.

2

What security implications are discussed in the article?

The article highlights the risk of using compromised VSCode extensions that could lead to unauthorized cryptomining on users' systems.

3

What products or software are affected by these malicious extensions?

The affected software includes Microsoft Visual Studio Code and its related extensions.

4

How do these malicious extensions operate?

The malicious extensions masquerade as legitimate development tools while secretly deploying the XMRig cryptominer.

5

What type of cryptocurrency do the cryptominers target?

The cryptominers specifically target Monero as their cryptocurrency.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203