VS Code Extensions: Risks and Mitigations | IFIN

You wouldn't download an infostealer right into your codebase, would you?

Just a few weeks ago, we were treated to another demonstration of the risks of code editor extensions—specifically, the Nx Console compromise that led to the leak of GitHub's internal repositories. Perhaps less world-rocking, but still newsworthy, was the Glassworm malware campaign, in which more than 70 extensions published to the OpenVSX extension repository. These extensions are an appealing attack vector for the baddies, owing to their low observability from security tools, implicit trust in extensions by users, and the likely impact radius when activated on developer systems. Oh, and not to mention: VS Code is cross-platform, so the attacks work on Windows, Linux, and macOS.


This is a companion discussion topic for the original entry at https://ifin-intel.org/blog/risky-vsx/
1 Like