Security researchers at Koi Security disclosed on January 26, 2026 that two Visual Studio Code extensions impersonating ChatGPT — installed a combined 1.5 million times — silently captured every file developers opened or edited and transmitted the contents, Base64-encoded, to a server in China. The extensions, published under the names “ChatGPT – 中文版” and “ChatGPT – ChatMoss”, functioned normally as AI coding assistants while covertly exfiltrating up to 50 files per workspace and fingerprinting devices via hidden analytics trackers. Neither extension had any actual affiliation with OpenAI.