AI VS Code forks push fake extensions, supply chain risk now

AI-powered VS Code forks recommended extensions missing from Open VSX, allowing attackers to claim unregistered namespaces and publish malicious packages that could expose secrets—vendors and the Eclipse Foundation have since implemented fixes and registry safeguards.

  • Several AI-powered forks of Microsoft Visual Studio Code (VS Code) recommended extensions that were not present in the Open VSX registry.
  • Unclaimed namespaces allowed anyone to register those extension names and upload packages, creating a supply-chain risk.
  • Attackers could publish malicious extensions that users install after seeing IDE recommendations, potentially exposing secrets and source code.
  • Vendors and the Eclipse Foundation implemented fixes and registry safeguards after responsible disclosure.

On Jan. 6, 2026, security researchers reported that AI-powered forks of Microsoft Visual Studio Code (VS Code) — including Cursor, Windsurf, Google Antigravity, and Trae — offered extension recommendations that did not exist in the Open VSX registry, creating a potential supply-chain risk, according to Malware“>Koi.

- Advertisement -

These IDEs inherit recommended extension lists from Microsoft’s marketplace. Recommendations appear in two ways: file-based prompts when opening certain file types, and software-based prompts when specific programs are installed on the host system.

Researcher Oren Yomtov described the core issue: “The problem: these recommended extensions didn’t exist on Open VSX.” Because the namespaces were unclaimed, anyone could register them and upload arbitrary packages to the registry.

As an example, an attacker could publish a package named ms-ossdata.vscode-postgresql. When a developer with PostgreSQL installed opens one of the affected IDEs, they might see “Recommended: PostgreSQL extension” and install the suggested package, which could execute malicious code and expose credentials, secrets, or source code.

Koi published placeholder packages to demonstrate the risk and reported that the PostgreSQL placeholder attracted about 500 installs. Other extension names claimed by Koi as placeholders included ms-azure-devops.azure-pipelines, msazurermtools.azurerm-vscode-tools, usqlextpublisher.usql-vscode-ext, cake-build.cake-vscode, and pkosta2005.heroku-command.

- Advertisement -

Following responsible disclosure, Cursor, Windsurf, and Google released fixes. The Eclipse Foundation removed non-official contributors from the registry and enforced broader safeguards. Developers are advised to verify publisher identities before installing recommended extensions.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

a16z Crypto buys BABY in $15M deal to boost Bitcoin DeFi Now

Babylon raised $15 million via a token sale to the digital asset arm of...

Black Cat SEO Poisoning Pushes Fake Apps, Installs Backdoor.

Black Cat used SEO poisoning to place fake software download pages high in search...

Caterpillar, NVIDIA Team Up to Add AI to Machines, Factories

Caterpillar Inc. expanded a partnership with NVIDIA to add AI across its machines, factories,...

Premier League crypto sponsors drop to 13 amid FCA warnings.

Thirteen of 20 Premier League clubs have crypto-related sponsors in the 2025/26 season.Socios is...

JPM Coin Moves to Canton Network for Near-Instant Use Today!

JPMorgan’s Kinexys will bring its JPM Coin to the privacy-enabled Canton Network in a...
- Advertisement -

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Bitcoin (BTC) $ 90,925.00 1.55%
Ethereum (ETH) $ 3,136.52 3.16%
XRP (XRP) $ 2.19 2.92%
Bittensor (TAO) $ 271.76 4.55%
Polkadot (DOT) $ 2.13 1.44%
Cardano (ADA) $ 0.400866 2.20%
Chainlink (LINK) $ 13.35 2.68%
Hyperliquid (HYPE) $ 26.86 1.84%
Monero (XMR) $ 438.99 1.64%
Hedera (HBAR) $ 0.122596 3.52%
Toncoin (TON) $ 1.87 1.15%