Security researchers reported multiple developer supply-chain threats abusing trusted ecosystems to steal data or deliver malware. In Microsoft’s VS Code Marketplace, two AI-themed extensions—ChatGPT – 中文版 (publisher WhenSunset, ~1.34M installs) and ChatMoss (CodeMoss) (publisher zhukunpeng, ~150K installs)—were found exfiltrating developer data to China-based servers without disclosure or consent. Koi Security attributed the activity to a campaign dubbed “MaliciousCorgi,” noting shared code and common backend infrastructure; the extensions reportedly monitor files opened in VS Code and transmit full contents (Base64-encoded), including subsequent changes.
Separately, malicious PyPI packages spellcheckerpy and spellcheckpy impersonated the legitimate pyspellchecker project and embedded a Base64-encoded downloader inside a seemingly legitimate Basque dictionary resource (resources/eu.json.gz). Aikido reported the attacker first published “dormant” versions (payload present but not executed), then enabled execution in spellcheckpy v1.2.0 by adding an obfuscated trigger that runs on import/initialization (e.g., when importing SpellChecker), ultimately downloading a full-featured Python RAT. Together, the incidents reinforce the risk of installing unvetted extensions and packages, even when they appear functional and reference legitimate upstream repos.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
By January 26, 2026, Koi Security also disclosed "PackageGate," six zero-day vulnerabilities affecting npm, pnpm, vlt, and Bun that could bypass lifecycle script and lockfile integrity protections. Fixes were released for pnpm, vlt, and Bun, while npm reportedly declined to issue a fix and stated that installing git dependencies implies trust in repository contents.
When the malicious VS Code extensions were publicly reported, Microsoft had been contacted for comment and the extensions were still available in the marketplace. By January 26, Microsoft had launched an investigation, though the extensions had not yet been removed according to reporting at the time.
Koi Security reported that the two VS Code extensions, installed about 1.5 million times, covertly sent opened file contents and subsequent edits to servers in China. The extensions could also receive a server-side command to harvest up to 50 workspace files, potentially exposing source code, credentials, .env files, and configuration data.
By January 2026, Koi Security identified two malicious Visual Studio Code Marketplace extensions, ChatGPT and ChatMoss/CodeMoss, masquerading as AI coding assistants. The extensions shared the same backend infrastructure and data-stealing code, leading researchers to track the activity as the "MaliciousCorgi" campaign.
On January 20–21, 2026, a malware detection pipeline identified the malicious PyPI packages spellcheckerpy and spellcheckpy. Analysis showed the second-stage RAT performed host fingerprinting, used a custom XOR-obfuscated protocol, disabled TLS certificate validation, and beaconed every five seconds for commands including arbitrary code execution.
On January 20–21, 2026, spellcheckpy version 1.2.0 introduced obfuscated code that reconstructs and invokes exec at runtime when SpellChecker is imported or instantiated. This change activated the hidden downloader, which fetched a second-stage Python RAT from updatenet[.]work and ran it filelessly.
Before execution was enabled, the PyPI packages spellcheckerpy and spellcheckpy were published while impersonating the legitimate pyspellchecker project and linking to its real GitHub repository. These early releases contained a concealed base64-encoded stage-1 downloader in a Basque dictionary resource file, but the payload was not yet triggered.
In November 2025, HelixGuard documented a malicious PyPI campaign involving a package named "spellcheckers" that used a similar Python RAT structure but different command-and-control domains. Later analysis suggested the January 2026 packages followed the same threat actor playbook.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceaikido.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.