Skip to main content

One post tagged with "AI Coding Tools"

Security research on AI-powered coding assistants and IDE extensions

View All Tags

Blackbox AI's VS Code extension can give attackers root access to your machine. The company has not responded in seven months.

· 18 min read
Dhayabaran V
Barrack AI

A security researcher at ERNW GmbH sent a crafted PNG image to Blackbox AI's VS Code extension. The extension read the image, followed the hidden instructions inside it, downloaded a reverse shell binary from an attacker-controlled server, executed it, and then, after being guilt-tripped into apologizing, ran the binary again with sudo privileges. Root access. From a PNG.

The Blackbox AI extension has been installed over 4.7 million times according to the company's own website. It runs shell commands, edits files, and launches a browser on your machine. Three independent security research teams have now documented critical vulnerabilities in it. The company behind it has not responded to a single disclosure attempt in over seven months.