Malicious VS Code extensions with 1.5 million installs stole source code
Researchers at Koi Security have uncovered two malicious VS Code extensions in a campaign they call MaliciousCorgi. The extensions were marketed as AI-powered coding assistants but carried covert functionality to profile users and harvest files at scale. They have since been removed from the VS Code marketplace, but were available until recently and had almost 1.5 million downloads combined. Although one of the extensions was reported as suspicious by Checkmarx on 31 October 2025, it took further third-party evidence and nearly three months before it was finally removed.
What this means for your organisation
Extensions in developer tooling run with the developer's own privileges and see everything the developer sees: source code, configuration files, keys and tokens sitting in the working directory. The three-month lag between the first report and removal shows the marketplace cannot be treated as a quality gate you can lean on. At the same time, the pressure to adopt AI assistants in development is high enough that extensions get installed faster than they get assessed.
Berigo recommends
- Introduce an allowlist for developer tool extensions, with security review preceding installation.
- Rotate keys and tokens that were accessible on machines where these extensions were installed.
- Keep secrets out of working directories and use a secrets service rather than local files.
- Set clear boundaries for AI tooling in development, including which code may be exposed to third parties.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch