Fake AI Coding Assistant on VS Code Installs Malware
Security researchers found a fake add-on for Visual Studio Code that claimed to be a free AI helper for Moltbot, a popular tool. The add-on appeared in the official VS Code store but secretly installed harmful software that let attackers take control of users’ computers. Moltbot does not have an official VS Code add-on, and attackers used its popularity to trick people. Microsoft has now removed the fake add-on.
After installation, the add-on ran automatically whenever VS Code was opened and downloaded harmful files from the attackers. This allowed them to quietly access and control the computer. Researchers also warned that many Moltbot setups are not well protected, leaving chat messages and login details exposed. Since Moltbot can send messages and perform actions for users, attackers could pretend to be them, steal information, or spread more harmful add-ons.
Safety Tips for Users:
- Install extensions only from trusted and verified developers
- Be cautious of “official” tools when no official plugin exists
- Review and remove unused or suspicious extensions
- Watch for unusual system behavior or unknown remote access
Source: https://thehackernews.com/2026/01/fake-moltbot-ai-coding-assistant-on-vs.html