Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    LG is giving a free mini-fridge when you buy a full size-what you know here

    August 5, 2025

    Sisa Open-SOS-Platform Für Digital Forensic

    August 5, 2025

    James Hells supported Lost Bitcoin Fortune to launch Difie tokens

    August 5, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Current VSCODE Extension $ 500K Crypto theft in Karsar IDE
    Security

    Current VSCODE Extension $ 500K Crypto theft in Karsar IDE

    PineapplesUpdateBy PineapplesUpdateJuly 15, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Current VSCODE Extension $ 500K Crypto theft in Karsar IDE
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Current VSCODE Extension $ 500K Crypto theft in Karsar IDE

    Cursor AI IDE Code Editor caused a fake extension remote access tools and infected equipment with infostals, which, in a case, caused a theft of $ 500,000 in cryptocurrency from a Russian Crypto Developer.

    Cursor AI IDE is an AI-managed development environment based on Microsoft’s visual studio code. This includes an option of visual studio marketplace support for Open VSX, which allows you to install VSCODE-compatible extension to expand the functionality of the software.

    Kaspersky Reports He was called to investigate a security incident, where a Russian developer, who worked in Cryptocurrency, reported that $ 500,00 was stolen from his computer in Crypto. There was no antivirus software installed in the machine, but it was called clean.

    George Kucherin, a security researcher for Kaspersky, obtained an image of the hard drive of the device, and after analyzing it, a malicious JavaScript file named Extension.JS is located in .cursor/Extensions Directorate.

    The extension was named “Solidity Language” and was published on the Open VSX Registry, which claims to be a Syntax Highlighting tool to work with the Ethereum Smart Contracts.

    Although plugin implemented validity Solidity syntax highlighting extensionThis actually executed an additional malicious payload to download an Angelic (.) SU from a remote host to a powershell script.

    Extension.js file executed remote powerrashel script
    Extension.js file executed remote powerrashel script
    Source: Kasperki

    The remote powerrashel script was checked whether the remote management tool screens was already established, and if not, another script was executed to install it.

    Once the screens was established, the danger actors received full remote access on the developer’s computer. Using the screenconnect, the danger actor uploaded and executed the VBScript files, which was used to download the additional payload in the device.

    In the attack, the final script downloaded a malicious executable from Archive (.) Org, which was a loader known as VMDETECTOR, which was established:

    • Quaser Rat: A remote access is capable of executing the command on trojan devices.
    • Purelogs theft: An infostealing malware that steals credentials and authentication cookies from web browsers, as well as steals cryptocurrency wallet.

    According to Kasperki, Open VSX showed that the extension was downloaded 54,000 times before being removed on 2 July. However, researchers believe that this install count was artificially inflated to give it a sense of validity.

    A day later, the attackers published an almost identical version under the name “Solidity”, extending the installed count to about two million for this extension.

    Download counts inflated for malicious extension
    Download counts inflated for malicious extension
    Source: Kasperki

    Kaspersky says that the actor of danger was able to rank his expansion more than one legitimate in open Vsx search results by gaming and inflated install count. The victim established malicious extensions, thinking that it was valid.

    Researchers published Microsoft’s Visual Studio Code Marketplace in a similar extension called “Solabot”, “Mount-Ath”, and “Blankebesxstnion”, which also executed a powerful script to establish screngcons and infosellers.

    Kasparki has warned that developers should be careful to download package and extension from open repository as they have become a common source of malware infections.

    “Malicious packages continue to pose a significant threat to the crypto industry. Today many projects rely on the open-source tool downloaded from the package repository,” Kaspasky is the conclusion.

    “Unfortunately, packages from these repository are often a source of malware infections. Therefore, we recommend excessive caution when downloading any equipment. Always verify that the package you are downloading is not fake.”

    “If a package does not work as advertised after installing it, be suspicious and check the downloaded source code.”


    Tines needle

    While cloud attacks can be more sophisticated, the attackers still succeed with surprisingly simple techniques.

    Drawing by the detection of Vij in thousands of organizations, this report reveals the 8 major techniques used by Claude-Floid danger actors.

    500K crypto Current extension Ide Karsar Theft VSCODE
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHackers love these 7 screenshots that you keep in your gallery
    Next Article Meta received Playai, a human -like voices that produce startups
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Sisa Open-SOS-Platform Für Digital Forensic

    August 5, 2025
    Security

    Amazon lets you buy cars now used in a few clicks – how is it here

    August 5, 2025
    Security

    Cyber attack in summer 2025

    August 5, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    LG is giving a free mini-fridge when you buy a full size-what you know here

    August 5, 2025

    Sisa Open-SOS-Platform Für Digital Forensic

    August 5, 2025

    James Hells supported Lost Bitcoin Fortune to launch Difie tokens

    August 5, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.