logo

Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces

ID: e060d6ed-ee30-5c76-a7e3-fb5615b9abae

STIX ID: report--e060d6ed-ee30-5c76-a7e3-fb5615b9abae

Feed Name: Wiz Blog

Threat Score
78/100

Date Published: 2025-10-15

Date Updated: 2026-05-01

...
...

Wiz Research discovered over 550 validated leaked secrets across more than 500 VSCode/Open VSX extensions — including 100+ valid VSCode Marketplace Personal Access Tokens and 30+ Open VSX tokens — creating a supply-chain risk where attackers could push malicious updates to a combined install base on the order of 150,000+ installs; Wiz worked with Microsoft to notify publishers, revoke exposed tokens, scan and remediate extensions, and develop platform-level mitigations and detection improvements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.