The VSCode Marketplace is pretty easy to hack with malicious extensions

Unlocked padlock on a computer keyboard



(Image credit: Unsplash / Fly:D)

VSCode Marketplace, a repository for Visual Studio Code (VSC) externsions, has poor security defenses, allowing threat actors to abuse it and distribute malicious code among the millions of its users, experts have warned.

A report from AquaSec tested the platform and concluded that abusing it to distribute malware (opens in new tab) was ridiculously easy. 

Furthermore, the researchers claim they weren’t the first to spot the flaws – some threat actors were already active. 

Spoofing important details

In a blog post (opens in new tab), AquaSec’s team outlined how it tried to upload a typosquatted, malicious version of a popular extension with 27 million downloads. 

It realized that the malware needed not even be typosquatted –  the platform has a feature called ‘displayName’ allowing the authors to name their extensions however they like – the name does not need to be unique. So, they named it exactly the same as the legitimate one.

Then, they realized that they could also use the same logo and description as the legitimate project.

Also, the details, while they get pulled from GitHub, can later be edited. That means that the attackers can easily spoof the project details and present the malware as a legitimate tool with a long development history. The only thing that couldn’t be spoofed was the number of downloads and the search ranking. 

“However, over time an increasing pool of unknowing users will have downloaded our faux extension. As these figures grow, the extension will gain credibility,” AquaSec said. “Additionally, since in the dark web it is possible to purchase various services, an extremely determined attacker could potentially manipulate these numbers by buying services which would inflate the number of downloads and stars.”

AquaSec also looked at the verification badge on VSCode Marketplace and concluded that the feature is meaningless, as any published with a purchased domain gets one, regardless of the relevance of the domain to the software project.

While the researchers only made a proof-of-concept, they also found actual malicious code lurking in the store. These are named “API Generator Plugin” and “code tester”.

Visual Studio Code is Microsoft’s source-code editor, used by some 70% of professional software developers worldwide, according to BleepingComputer. The extensions can be used to install additional programs, steal source code, or tamper with it in other ways in the VSCode IDE.

Via: BleepingComputer (opens in new tab)

Sign up to theTechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read More
Margarett Mcnaught

Latest

BusinessDay 21st Apr 2026

Business Day, established in 2001, is a daily business newspaper based in Lagos. It is the only Nigerian newspaper with a bureau in Accra, Ghana. It has both daily and Sunday titles. It circulates in Nigeria and Ghana... Read More... Phone:+234-803-322-5506 |+234-802-601-1296 |+234-813-346-4051

Liverpool transfer news: Reds ‘plotting’ move for Sunderland favourite this summer

Liverpool are reportedly interested in signing Sunderland midfielder Enzo Le Fee during the summer transfer window. The Reds are preparing for a busy off-season trading point, with the 20-time English champions looking to replace outgoing legend Mohamed Salah, who leaves a major gap on the right flank of the Anfield club. As a result, Liverpool

John Ternus is not inheriting your father’s Apple

Image: Apple/Youtube It’s only Tuesday morning but there’s already blockbuster news this week that will change the course of Apple events. And that is that the third macOS Tahoe beta is available to developers. Ha-ha! No, that’s not it. It’s that in the middle of writing this column that was going to be about the

Mountain Mike’s Pizza Brings Sports Fans Together for Great Games and Great Food With New Triple Play Bundle

Mountain Mike’s Pizza Brings Big Flavor to Gameday with the Triple Play Bundle Leading Family-Style Pizza Chain Reinforces its Reputation as the Go-To Destination on Gameday for Watch Parties and Shared Sports Moments Irvine, CA  ( RestaurantNews.com )   Mountain Mike’s Pizza , a leading family-style pizza chain for nearly 50 years, and home of

Newsletter

Don't miss

BusinessDay 21st Apr 2026

Business Day, established in 2001, is a daily business newspaper based in Lagos. It is the only Nigerian newspaper with a bureau in Accra, Ghana. It has both daily and Sunday titles. It circulates in Nigeria and Ghana... Read More... Phone:+234-803-322-5506 |+234-802-601-1296 |+234-813-346-4051

Liverpool transfer news: Reds ‘plotting’ move for Sunderland favourite this summer

Liverpool are reportedly interested in signing Sunderland midfielder Enzo Le Fee during the summer transfer window. The Reds are preparing for a busy off-season trading point, with the 20-time English champions looking to replace outgoing legend Mohamed Salah, who leaves a major gap on the right flank of the Anfield club. As a result, Liverpool

John Ternus is not inheriting your father’s Apple

Image: Apple/Youtube It’s only Tuesday morning but there’s already blockbuster news this week that will change the course of Apple events. And that is that the third macOS Tahoe beta is available to developers. Ha-ha! No, that’s not it. It’s that in the middle of writing this column that was going to be about the

Mountain Mike’s Pizza Brings Sports Fans Together for Great Games and Great Food With New Triple Play Bundle

Mountain Mike’s Pizza Brings Big Flavor to Gameday with the Triple Play Bundle Leading Family-Style Pizza Chain Reinforces its Reputation as the Go-To Destination on Gameday for Watch Parties and Shared Sports Moments Irvine, CA  ( RestaurantNews.com )   Mountain Mike’s Pizza , a leading family-style pizza chain for nearly 50 years, and home of

Xiaomi boosts EV business with new hires, including first CTO appointment

News Written by Cheng Zi Published on 21 Apr 2026  4 mins read Xiaomi announced on April 17 in an internal email that Hu Zhengnan had been appointed vice president of Xiaomi and CTO of its automotive division, while Song Gang had been named vice president of the automotive division and chief of staff, sources told 36Kr. It

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western