Attackers Exploit IDE Extensions Like VSCode to Bypass Trust Checks and Infect Developer Systems
ID: cbd7368e-e295-5385-a3cd-a09cc9c659e4
STIX ID: report--cbd7368e-e295-5385-a3cd-a09cc9c659e4
Feed Name: Cyber Press
OX researchers discovered that popular IDEs (Visual Studio Code, Visual Studio, IntelliJ IDEA, and Cursor) use extension verification mechanisms that can be subverted by manipulating extension metadata; attackers can forge packages that retain the verified badge while embedding arbitrary code. Proof-of-concept malicious extensions were created to open the system calculator, demonstrating how verified-looking extensions—especially those installed from sources like GitHub as VSIX or ZIP bundles—could execute code on developer workstations, posing supply-chain, data-theft, and ransomware risks; developers are advised to vet extensions and await platform fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
