Settings

Theme

Malicious AI extensions on VS Code Marketplace steal developer data

bleepingcomputer.com

3 points by oenton a month ago · 1 comment

Reader

oentonOP a month ago

TLDR - malicious VS Code extension named "ChatGPT" sends the full contents of any file you open to servers based in China by using a hidden iframe in a webview. There's a second mechanism that runs a command that bulk sends 50 files at a time from your workspace to the same servers. Third also uses a hidden iframe (zero pixels) in a webview to load 4 SDKs that track activity in the editor.

I have to admit I laughed when I saw the marketplace screenshot of "ChatGPT" from some unknown author (not OpenAI or Microsoft) with a non-English description. If anything screams "sus" to me that would be it.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection