CyberHappenings logo
☰

Track cybersecurity events as they unfold. Sourced timelines, daily updates. Fast, privacy‑respecting. No ads, no tracking.

WhiteCobra targets code editors with malicious extensions

First reported
Last updated
πŸ“° 1 unique sources, 1 articles

Summary

Hide β–²

A threat actor named WhiteCobra is targeting users of VSCode, Cursor, and Windsurf code editors by uploading malicious extensions to the Visual Studio marketplace and the Open VSX registry. The campaign, which is ongoing, has already resulted in significant financial losses, including a $500,000 crypto-theft in July. The extensions, which appear legitimate, are designed to steal cryptocurrency and other sensitive information. The threat actor exploits the cross-compatibility of VSIX extensions and the lack of rigorous submission reviews on these platforms. WhiteCobra continuously uploads new malicious code to replace extensions that are removed, demonstrating a high level of organization and persistence.

Timeline

  1. 13.09.2025 17:00 πŸ“° 1 articles Β· ⏱ 1d ago

    WhiteCobra targets code editors with malicious extensions

    A threat actor named WhiteCobra has uploaded 24 malicious extensions to the Visual Studio marketplace and the Open VSX registry, targeting users of VSCode, Cursor, and Windsurf. The campaign is ongoing, with new malicious code continuously uploaded to replace removed extensions. The extensions appear legitimate and have resulted in significant financial losses, including a $500,000 crypto-theft in July. The payloads are platform-specific and include the LummaStealer malware on Windows and an unknown malware family on macOS.

    Show sources

Information Snippets