logo

Introducing IDE-SHEPHERD: Your shield against threat actors lurking in your IDE

ID: 46231bac-5a70-54ca-b94b-287747467326

STIX ID: report--46231bac-5a70-54ca-b94b-287747467326

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2026-01-26

Date Updated: 2026-04-27

...
...

This report introduces IDE-SHEPHERD, an open-source VS Code/Cursor extension that instruments the extension-host Node.js runtime to intercept child_process, HTTP(S), and task executions, and uses heuristic metadata analysis to detect and block malicious extensions and workspace tasks; the document demonstrates protections against real-world malicious extension campaigns (including obfuscated payloads and folder-open task execution), lists example IoCs, and advocates for continuous, runtime-based defenses to mitigate IDE-based supply-chain and workspace-trust abuses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.