Threat · curated 4 Aug 2026
CodeRelay: 12 VS Code Extensions Disguised as Developer Tools
First reported knostic.ai
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
CodeRelay shows attackers weaponizing trojanized developer tooling to silently exfiltrate sensitive AI-assistant chat and source code to attacker-controlled LLM services, a supply-chain vector that bypasses conventional data-loss controls.
Knostic reports a coordinated campaign it dubbed "CodeRelay," involving 13 malicious VSIX packages across 12 VS Code extensions disguised as compilers, code runners, and "timeline" tools. Based on static analysis, the extensions are written to relay a developer's chat text, pasted code, and prior conversation history to one of three external LLM endpoints using embedded API keys, with ten hiding the logic in a compressed runtime-decoded payload and five using Unicode homoglyphs or invisible characters to disguise their names.