[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3jdlzjaU9nx6nmTLjeSCA3qFd9eMJVcoWsr-VKcQx2U":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"ea972649-d03a-4ad3-8fd3-64de4e14da73","malicious-vs-code-extensions-threaten-developer-supply-chains","cbf4c1a3-684c-4861-95ee-280f8114cb66","Malicious VS Code Extensions Threaten Developer Supply Chains","Developer tooling ecosystems like the VS Code Marketplace represent a critical but often overlooked attack surface in the software supply chain. Threat actors embed malicious code into seemingly legitimate extensions, gaining execution access within developer environments where sensitive credentials, source code, and internal systems are routinely accessed. The GitHub breach involving a malicious VS Code extension illustrates how a single compromised tool can cascade into broader organizational compromise. Without proactive scanning, developers unknowingly adopt risky extensions, making the entire development pipeline a vector for supply chain attacks. Automated security analysis tools like Socket's extension scanner are essential for closing this visibility gap before harm occurs.","**Immediate actions:**\n- Audit all currently installed VS Code extensions across developer workstations and remove any that are unverified or unmaintained.\n- Integrate a supply chain scanning tool (e.g., Socket) into your developer onboarding and CI\u002FCD processes to flag malicious extensions before adoption.\n\n**Long-term improvements:**\n- Establish and enforce an approved extension allowlist through organizational policy, preventing developers from installing unapproved VS Code extensions.\n- Implement a formal third-party tool vetting process that evaluates extension publishers, permissions, and code behavior before enterprise approval.\n- Treat developer workstations and IDEs as part of the threat model in your software supply chain security program.\n\n**Detection measures:**\n- Monitor developer endpoints for anomalous network connections or file system access that may originate from IDE extension processes.\n- Subscribe to threat intelligence feeds and security advisories specifically covering developer tooling and marketplace ecosystems to stay ahead of emerging threats.",[12,13,14,15,16,17,18],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-218 (SSDF) PW.4: Reuse Existing, Well-Secured Software","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST CSF ID.SC-3: Suppliers and third-party partners are assessed","SLSA Supply Chain Levels for Software Artifacts (provenance verification)","ISO\u002FIEC 27036: Information security for supplier relationships","published","2026-10-06T20:20:39.750514+00:00","2026-10-06T20:20:39.476+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fvscode-extensions?utm_medium=feed","introducing-socket-scanning-for-vs-code-marketplace-extensions-6e30bc","Introducing Socket Scanning for VS Code Marketplace Extensions",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":34,"name":35,"slug":36,"description":37,"color":38},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]