logo

VSCode IDE forks expose users to "recommended extension" attacks

ID: 1268158f-7404-5a33-8a0e-31d03c435bb1

STIX ID: report--1268158f-7404-5a33-8a0e-31d03c435bb1

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2026-01-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Popular VSCode forks (Cursor, Windsurf, Google Antigravity, Trae) inherited hardcoded extension recommendations that point to Microsoft’s Visual Studio Marketplace but are unsupported on OpenVSX. Several recommended publisher namespaces were unclaimed, allowing an attacker to register those namespaces and publish malicious extensions that users might trust based on IDE recommendations. Koi researchers registered placeholder extensions to block abuse and coordinated with OpenVSX and vendors; Cursor and Google have applied fixes, Windsurf had not responded at the time of reporting, and no evidence of active exploitation was found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.