logo

Cursor, Windsurf & Google Antigravity IDEs Linked to Malicious Extension Exposure

ID: 88f7f419-09bb-5952-ba84-0819bef19332

STIX ID: report--88f7f419-09bb-5952-ba84-0819bef19332

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Divya

...
...

A critical supply-chain vulnerability in popular AI-powered IDE forks of VS Code (Cursor, Windsurf, Google Antigravity) allowed attackers to claim unregistered Microsoft-extension names on the OpenVSX registry and upload malicious extensions that the IDEs would auto-recommend. Researchers proved the issue by publishing harmless placeholder extensions that more than 1,000 developers installed; Cursor and Google have since rolled out fixes, Windsurf reportedly did not respond, and the Eclipse Foundation has taken steps to verify namespaces and remove unauthorized contributors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.