logo

Can You Trust Your VSCode Extensions?

ID: e16ea76c-6d59-53c5-9e76-ac2fe9bb75be

STIX ID: report--e16ea76c-6d59-53c5-9e76-ac2fe9bb75be

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2023-01-06

Date Updated: 2026-04-26

...
...

Aqua Nautilus researchers demonstrate that the VSCode Marketplace permits impersonation and typosquatting of popular extensions, enabling attackers to publish malicious extensions that execute arbitrary code with the user's privileges (including fetching and eval-ing remote payloads over insecure HTTP); their POC masquerading as Prettier achieved 1,000+ installs in 48 hours, highlighting significant supply-chain and developer-targeting risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.