Skip to main content
← All Articles

Tag

#VS Code

12 articles

Advertisement

SU
HIGH
Supply Chain

VS Code Marketplace Abuse: Detecting Malicious Developer Extensions

Researchers identify malicious Visual Studio Code extensions exfiltrating source code and credentials. Learn how to secure your development environment.

Runtime Rebel Intel
3 min read · Jul 27, 2026
GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code
HIGH
Vulnerabilities

GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code

New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.

Runtime Rebel Intel
4 min read · Jun 3, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach Linked to TanStack Supply Chain Attack

GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.

Runtime Rebel Intel
4 min read · May 21, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension

GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.

Runtime Rebel Intel
4 min read · May 20, 2026
Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer
HIGH
Supply Chain

Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer

Security researchers have identified a compromised version of the Nx Console VS Code extension (18.95.0) containing a malicious credential stealer.

Runtime Rebel Intel
3 min read · May 19, 2026
GlassWorm Campaign Leverages Malicious VS Code Extensions
MEDIUM
Supply Chain

GlassWorm Campaign Leverages Malicious VS Code Extensions

Runtime Rebel details the GlassWorm campaign, which infects developers via malicious Visual Studio Code extensions on Open VSX, facilitating a supply chain attack.

Runtime Rebel Intel
5 min read · Apr 28, 2026
SU
MEDIUM
Supply Chain

GlassWorm Malware: Cloned Open VSX Extensions Target Developers

Over 70 malicious Open VSX extensions cloned from popular tools deliver GlassWorm malware, highlighting risks in developer-focused supply chain attacks.

Runtime Rebel Intel
3 min read · Apr 28, 2026
SU
HIGH
Supply Chain

Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments

A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.

Runtime Rebel Intel
4 min read · Apr 23, 2026
Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk
HIGH
Supply Chain

Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk

A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.

Runtime Rebel Intel
3 min read · Mar 27, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code

TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.

Runtime Rebel Intel
4 min read · Mar 25, 2026
Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack
HIGH
Supply Chain

Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack

TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.

Runtime Rebel Intel
5 min read · Mar 25, 2026
GlassWorm Abuses Open VSX Registry in Supply-Chain Attack
HIGH
Supply Chain

GlassWorm Abuses Open VSX Registry in Supply-Chain Attack

The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.

Runtime Rebel Intel
3 min read · Mar 14, 2026