
"A threat group is dropping two dozen malicious extensions into the VSCode and Open VSX marketplaces, targeting developers using the VSCode, Cursor, and Windsurf source code editing tools with the goal of draining cryptocurrency wallets. Researchers with security firm Koi Security have been tracking WhiteCobra's activities for more than a year as the bad actors have continued to push new malicious extensions - on a weekly basis - as others are being detected and taken down."
"Koi's Ronen noted that Cole "is not just any victim, he's a security professional with a decade of security experience, hinting on the level of sophistication these attacks have achieved." He wrote that Koi had reported about a new wave of malicious extensions that have since been taken down, but that "WhiteCobra continues to upload new malicious extensions on a weekly basis, including just this week. Making [Cole] far less likely from being the last victim.""
"In August, Zak Cole, an Ethereum developer, reported in a post on X (formerly Twitter) that his crypto wallet was drained. "I've been in crypto for over 10 years and I've Never been hacked. Perfect OpSec record," Cole wrote. "Yesterday, my wallet was drained by a malicious @cursor_ai extension for the first time. If it can happen to me, it can happen to you.""
WhiteCobra has operated for more than a year, repeatedly publishing malicious extensions in the VSCode and Open VSX marketplaces. Approximately two dozen malicious extensions target developers using VSCode, Cursor, and Windsurf to harvest keys and drain cryptocurrency wallets. Confirmed thefts include $500,000 from a Russian blockchain developer in June and the draining of an Ethereum developer's wallet in August. The group can launch a new campaign in under three hours, quickly packaging, promoting, and profiting. A captured playbook and deployment plan detail operations, infrastructure, promotional strategies, and projected revenues, enabling rapid campaign replication.
Read at DevOps.com
Unable to calculate read time
Collection
[
|
...
]