Tag: supply chain risk

VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX
News

VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX

It has been discovered that well-known AI-powered Microsoft Visual Studio Code (VS Code) forks like Cursor, Windsurf, Google Antigravity, and Trae suggest extensions that aren't listed in the Open VSX registry, which could put supply chains at risk when malicious packages are published under those names. These integrated development environments (IDEs) inherit the list of officially recommended extensions from Microsoft's extensions marketplace, which is the issue, according to Koi. Open VSX does not have these extensions. There are two types of VS Code extension recommendations: software-based, which are recommended when relevant apps are already installed on the host, and file-based, which are shown as toast notifications when users open a file in a particular format. The probl...
Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks
News

Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks

A serious supply chain risk has been identified by cybersecurity researchers due to a key vulnerability in the Open VSX Registry ("open-vsx[.]org") that, if successfully exploited, might have allowed attackers to take over the whole Visual Studio Code extensions marketplace. According to researcher Oren Yomtov of Koi Security, this flaw gives attackers complete access over the marketplace for extensions, which in turn gives them complete control over millions of developer computers. A hostile actor could release harmful updates to all Open VSX extensions by taking advantage of a CI flaw. The maintainers recommended several iterations of changes after responsible disclosure on May 4, 2025, and a final patch was released on June 25. An open-source project that serves as a substitut...