logo

The Wild West of VS Code extensions and how a poisoned extension breached GitHub

ID: 4a069d89-8873-531b-bacb-b0522de71c80

STIX ID: report--4a069d89-8873-531b-bacb-b0522de71c80

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-05-20

Date Updated: 2026-07-24

...
...

The report details a supply-chain compromise of the Nx Console VS Code extension (2.2M installs) published with a stolen GitHub token, which was auto-distributed to users during an 18-minute window on the Visual Studio Marketplace (36 minutes on OpenVSX). It highlights how default automatic extension updates allowed rapid, large-scale distribution of a small injected JavaScript payload that fetched an obfuscated dropper to exfiltrate credentials, links the incident to prior AsyncAPI compromises, and recommends immediate remediation (rotate tokens/keys) and policy mitigations (auto-update cooldowns or device-level holds).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.