The Wild West of VS Code extensions and how a poisoned extension breached GitHub
ID: 4a069d89-8873-531b-bacb-b0522de71c80
STIX ID: report--4a069d89-8873-531b-bacb-b0522de71c80
Feed Name: Aikido Security's Blog
The report details a supply-chain compromise of the Nx Console VS Code extension (2.2M installs) published with a stolen GitHub token, which was auto-distributed to users during an 18-minute window on the Visual Studio Marketplace (36 minutes on OpenVSX). It highlights how default automatic extension updates allowed rapid, large-scale distribution of a small injected JavaScript payload that fetched an obfuscated dropper to exfiltrate credentials, links the incident to prior AsyncAPI compromises, and recommends immediate remediation (rotate tokens/keys) and policy mitigations (auto-update cooldowns or device-level holds).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
