HomeSecurityOver 100 VS Code extensions expose developers

Over 100 VS Code extensions expose developers

New research has revealed that publishers of over 100 Visual Studio Code (VS Code) extensions leaked access tokens that could be exploited by malicious actors to update the extensions, creating a critical risk to the software supply chain. Cloud security firm Wiz noted that in many cases, publishers failed to take into account the fact that VS Code extensions, while distributed as .vsix files , can be unzipped and inspected, revealing embedded secrets.

See also: Red Hat: Hackers claim breach of 28,000 private GitHub repositories

VS Code

Wiz found over 550 validated secrets distributed across more than 500 extensions from hundreds of different publishers. The 550 secrets belong to 67 different types, including:

– AI provider secrets, such as those related to OpenAI, Gemini, Anthropic, XAI, DeepSeek, Hugging Face , and Perplexity

– Secrets of cloud service providers, such as those related to Amazon Web Services (AWS), Google Cloud, GitHub, Stripe , and Auth0

– Database secrets, such as those related to MongoDB, PostgreSQL , and Supabase

Wiz also noted that more than 100 extensions leaked VS Code Marketplace PATs, corresponding to over 85,000 installs. Another 30 extensions with a cumulative install base of no less than 100,000 were found to be leaking Open VSX Access Tokens. A significant portion of the flagged extensions are themes.

See also: CISA: Shai-Hulud worm has compromised 500+ npm packages

Over 100 VS Code extensions expose developers

With Open VSX built into AI-powered VS Code forks like Cursor and Windsurf, extensions that leak access tokens can significantly expand the attack surface. In one case, the company identified a VS Code Marketplace PAT that could allow targeted malware to be pushed to the workforce of a Chinese giant with a market cap of $30 billion, suggesting that the problem also extends to internal or vendor-specific extensions used by organizations.

After a responsible disclosure to Microsoft in late March and April 2025, the Windows maker retracted the leaked PATs and announced that it was adding secret scanning capabilities to block extensions with validated secrets and notify developers when secrets are detected. VS Code users are advised to limit the number of extensions installed, carefully review extensions before downloading them, and weigh the pros and cons of enabling automatic updates.

See also: TP-Link Routers: PoC exploit for zero-day released

EDR

Organizations are recommended to develop an extension inventory to better respond to reports of malicious extensions and consider a central whitelist of allowed extensions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS