• News/
  • https://www.bleepingcomputer.com/news/security/whitecobra-floods-vscode-market-with-crypto-stealing-extensions/

'WhiteCobra' floods VSCode market with crypto-stealing extensions

BleepingComputer
·
Bill Toulas
·
Published Sep 13, 2025
·
Updated

A threat actor named WhiteCobra has targeting VSCode, Cursor, and Windsurf users by planting 24 malicious extensions in the Visual Studio marketplace and the Open VSX registry. The campaign is ongoing as the threat actor continuously uploads new malicious code to replace the extensions that are removed. In a public post, core Ethereum developer Zak Cole described how his wallet was drained after using a seemingly legitimate extension (contractshark.solidity-lang) for Cursor code editor.

Cole explained that the extension featured all the signs of a benign product with professionally designed icon, a detailed description, and 54,000 downloads on OpenVSX, Cursor's official registry. WhiteCobra is the same group responsible for the $500,000 crypto-theft in July, through a fake extension for the Cursor editor, according to researchers at endpoint security provider Koi. VS (Visual Studio) Code, Cursor, and Windsurf are code editors supporting the VSIX extension - the default package format for extensions published on the VS Code Marketplace and the OpenVSX platform. This cross-compatibility and the lack of proper submission review on these platforms make them ideal for attackers looking to run campaigns with a broad reach. According to Koi Security, WhiteCobra creates malicious VSIX extensions that appear legitimate due to an overall carefully created description and inflated download count. Koi Security discovered that the following extensions are part of the latest WhiteCobra c...

Read full article

Affected Software

3 affected components
Microsoft Visual Studio Code
Cursor Cursor
Windsurf Windsurf
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security threat involving the 'WhiteCobra' group that has introduced 24 malicious crypto-stealing extensions in the VSCode market.

2

What are the potential security implications mentioned?

The malicious extensions can compromise users' cryptocurrency assets by stealing sensitive information.

3

Which software platforms are primarily affected by this threat?

The affected software includes Microsoft Visual Studio Code, Cursor, and Windsurf.

4

How many malicious extensions have been identified in the campaign?

The campaign has introduced 24 malicious extensions into the marketplace.

5

Is the threat actor's campaign still ongoing?

Yes, the threat actor WhiteCobra is actively continuing their campaign.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203