<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #VS Code</title><description>Cybersecurity articles tagged #VS Code on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>VS Code Marketplace Abuse: Detecting Malicious Developer Extensions</title><link>https://runtimerebel.com/blog/vs-code-marketplace-abuse-detecting-malicious-developer-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/vs-code-marketplace-abuse-detecting-malicious-developer-extensions</guid><description>Researchers identify malicious Visual Studio Code extensions exfiltrating source code and credentials. Learn how to secure your development environment.</description><pubDate>Mon, 27 Jul 2026 03:19:47 GMT</pubDate><category>VS Code</category><category>Marketplace Security</category><category>Developer Security</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code</title><link>https://runtimerebel.com/blog/github-dev-one-click-attack-stealing-oauth-tokens-via-vs-code</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-dev-one-click-attack-stealing-oauth-tokens-via-vs-code</guid><description>New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.</description><pubDate>Wed, 03 Jun 2026 13:47:14 GMT</pubDate><category>GitHub</category><category>VS Code</category><category>Oauth Theft</category><category>URI Handler</category></item><item><title>GitHub Repository Breach Linked to TanStack Supply Chain Attack</title><link>https://runtimerebel.com/blog/github-repository-breach-linked-to-tanstack-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-repository-breach-linked-to-tanstack-supply-chain-attack</guid><description>GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.</description><pubDate>Thu, 21 May 2026 09:15:44 GMT</pubDate><category>GitHub</category><category>TanStack</category><category>NPM</category><category>Supply Chain Attack</category><category>VS Code</category></item><item><title>GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension</title><link>https://runtimerebel.com/blog/github-repository-breach-3800-repos-accessed-via-vs-code-extension</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-repository-breach-3800-repos-accessed-via-vs-code-extension</guid><description>GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.</description><pubDate>Wed, 20 May 2026 09:15:55 GMT</pubDate><category>GitHub</category><category>VS Code</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer</title><link>https://runtimerebel.com/blog/nx-console-18-95-0-compromise-vs-code-extension-credential-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/nx-console-18-95-0-compromise-vs-code-extension-credential-stealer</guid><description>Security researchers have identified a compromised version of the Nx Console VS Code extension (18.95.0) containing a malicious credential stealer.</description><pubDate>Tue, 19 May 2026 09:18:11 GMT</pubDate><category>Nx Console</category><category>VS Code</category><category>Supply Chain Attack</category><category>Rwl Angular Console</category><category>Credential Stealer</category></item><item><title>GlassWorm Campaign Leverages Malicious VS Code Extensions</title><link>https://runtimerebel.com/blog/glassworm-campaign-leverages-malicious-vs-code-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-campaign-leverages-malicious-vs-code-extensions</guid><description>Runtime Rebel details the GlassWorm campaign, which infects developers via malicious Visual Studio Code extensions on Open VSX, facilitating a supply chain attack.</description><pubDate>Tue, 28 Apr 2026 16:45:38 GMT</pubDate><category>GlassWorm</category><category>VS Code</category><category>Open VSX</category><category>Supply Chain Attack</category><category>Malware</category><category>Developer Tools</category><category>Application Security</category></item><item><title>GlassWorm Malware: Cloned Open VSX Extensions Target Developers</title><link>https://runtimerebel.com/blog/glassworm-malware-cloned-open-vsx-extensions-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-cloned-open-vsx-extensions-target-developers</guid><description>Over 70 malicious Open VSX extensions cloned from popular tools deliver GlassWorm malware, highlighting risks in developer-focused supply chain attacks.</description><pubDate>Tue, 28 Apr 2026 12:45:16 GMT</pubDate><category>Open VSX</category><category>GlassWorm</category><category>VS Code</category><category>Checkmarx</category><category>Malware</category><category>Supply Chain Attack</category></item><item><title>Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments</title><link>https://runtimerebel.com/blog/compromised-checkmarx-kics-supply-chain-attack-on-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-checkmarx-kics-supply-chain-attack-on-developer-environments</guid><description>A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.</description><pubDate>Thu, 23 Apr 2026 16:40:50 GMT</pubDate><category>Checkmarx</category><category>KICS</category><category>Supply Chain Attack</category><category>Developer Tools</category><category>VS Code</category><category>Docker</category><category>Data Theft</category></item><item><title>Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk</title><link>https://runtimerebel.com/blog/open-vsx-registry-security-bypass-malicious-vs-code-extensions-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-vsx-registry-security-bypass-malicious-vs-code-extensions-risk</guid><description>A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.</description><pubDate>Fri, 27 Mar 2026 16:23:33 GMT</pubDate><category>Open VSX</category><category>VS Code</category><category>Supply Chain</category><category>Security Bypass</category><category>VSCodium</category></item><item><title>TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attacks-target-docker-hub-pypi-and-vs-code</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attacks-target-docker-hub-pypi-and-vs-code</guid><description>TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.</description><pubDate>Wed, 25 Mar 2026 12:24:38 GMT</pubDate><category>TeamPCP</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Docker Hub</category><category>GitHub Actions</category><category>VS Code</category></item><item><title>Checkmarx KICS &amp; VS Code Plugin Targeted in Supply Chain Attack</title><link>https://runtimerebel.com/blog/checkmarx-kics-vs-code-plugin-targeted-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-kics-vs-code-plugin-targeted-in-supply-chain-attack</guid><description>TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.</description><pubDate>Wed, 25 Mar 2026 00:37:08 GMT</pubDate><category>TeamPCP</category><category>Checkmarx KICS</category><category>VS Code</category><category>LiteLLM</category><category>Supply Chain Attack</category></item><item><title>GlassWorm Abuses Open VSX Registry in Supply-Chain Attack</title><link>https://runtimerebel.com/blog/glassworm-abuses-open-vsx-registry-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-abuses-open-vsx-registry-in-supply-chain-attack</guid><description>The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.</description><pubDate>Sat, 14 Mar 2026 16:10:23 GMT</pubDate><category>GlassWorm</category><category>Open VSX</category><category>Supply Chain Attack</category><category>VS Code</category><category>Malware</category></item></channel></rss>