JavaScript Congress • Nov 24, 2021

Vulnerable VS Code extensions are now at your front door

Raul Onitza-Klugman , Kirill Efimov

Security researchers analyzed the VS Code marketplace. Their findings are alarming. Discover how attackers weaponize popular extensions to steal SSH keys and execute remote code on developer machines.

Pause
Mute Enter Fullscreen
#1 about 4 min

The impact of digital transformation on developer roles

Cloud computing transfers infrastructure and network configuration responsibilities directly to application developers.

#2 about 3 min

Shifting security testing left in the software cycle

Integrating static analysis and software composition analysis early reduces the cost of fixing vulnerabilities.

#3 about 2 min

Managing vulnerabilities in transitive software dependencies

Developers must triage and update third-party packages to prevent exploits within an application's dependency tree.

#4 about 6 min

Real-world examples of software supply chain attacks

Threat actors distribute malicious packages and exploit unpatched dependencies to compromise developer workstations and organizational networks.

#5 about 5 min

Visual Studio Code as a target for exploitation

The massive market of open-source editor extensions introduces a significant attack surface for remote code execution.

#6 about 2 min

Automating vulnerability research in the extension marketplace

A custom processing pipeline uses headless servers to dynamically analyze zipped extension archives for security flaws.

#7 about 6 min

Path traversal vulnerabilities in local development servers

Insufficient path sanitization in local preview servers exposes sensitive local files to external query manipulation.

#8 about 5 min

Bypassing local server CORS restrictions using cross-site scripting

Injecting executable payloads into a vulnerable local server circumvent browser-based cross-origin resource sharing policies.

#9 about 6 min

Chaining automatic browser downloads with local path traversal

Forcing a background file download enables an external site to execute local scripts and exfiltrate secure keys.

#10 about 5 min

Exploiting websocket ports to execute arbitrary commands locally

Bruteforcing local connection ports via image tags allows attackers to trigger external API calls from compromised extensions.

#11 about 4 min

Mitigating extension vulnerabilities and applying workspace trust

Enforcing code execution barriers and auditing third-party tools protects developer environments from persistent threats.

Matching moments

5:44 min

Risks of malicious VS Code extensions and AI assistants

Chris Heilmann Chris Heilmann +3 · LIVE

4:53 min

Introduction to VS Code security risks and threat models

Thomas Chauchefoin +1 · World Congress 2023

2:17 min

Security incidents in extension marketplaces and package managers

Chris Heilmann Chris Heilmann +2 · LIVE

5:26 min

Exploiting path traversal vulnerabilities in code editor extensions

Sonya Moisset · World Congress 2023

2:14 min

Exploiting exposed network services in developer IDE extensions

Thomas Chauchefoin +1 · World Congress 2023

49 sec

Targeting developer integrated development environments and plugins

Vandana Verma · LIVE