> Markdown version of [/videos/283-vulnerable-vs-code-extensions-are-now-at-your-front-door](https://www.wearedevelopers.com/videos/283-vulnerable-vs-code-extensions-are-now-at-your-front-door). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerable VS Code extensions are now at your front door Security researchers analyzed the VS Code marketplace. Their findings are alarming. Discover how attackers weaponize popular extensions to steal SSH keys and execute remote code on developer machines. - **Speakers:** Raul Onitza-Klugman, Kirill Efimov - **Event:** JavaScript Congress - **Published:** November 24, 2021 - **Duration:** 44:11 - **URL:** https://www.wearedevelopers.com/videos/283-vulnerable-vs-code-extensions-are-now-at-your-front-door ## Summary As digital transformation accelerates and security "shifts left," developers have become prime targets for cyberattacks. Cybercriminals increasingly focus on developer tools to execute supply chain attacks, turning local environments into organizational gateways. Visual Studio Code, with over 14 million users and a massive extension marketplace containing over 25,000 NPM-based projects, represents a significant and often overlooked attack surface. To expose these risks, security researchers built a custom processing pipeline to analyze the VS Code marketplace using static and dynamic analysis. Their research uncovered critical vulnerabilities in popular extensions. For example, the *Instant Markdown* extension harbored a path traversal flaw that, when combined with a downloaded XSS payload, allowed attackers to bypass CORS policies and exfiltrate sensitive local files like SSH keys. Similarly, the *LaTeX Workshop* extension contained a command execution vulnerability where malicious actors could brute-force local WebSocket ports via hidden image tags to achieve remote code execution (RCE) on a developer's machine. Because VS Code extensions run with local privileges, compromising a single developer's IDE can easily pivot into a full-blown organizational breach. Mitigating these risks requires strict "extension hygiene" akin to third-party package management. Organizations and developers must rely on actively maintained extensions, integrate vulnerability scanners into their pipelines, and recognize that while features like VS Code's Workspace Trust are helpful, they do not fully protect against exploits executing within inherently trusted code environments. **Keywords:** vs code extension security, supply chain attacks, shift-left security testing, path traversal vulnerabilities, cors bypass techniques, xss payload injection, npm dependency vulnerabilities, local server exploits, websocket brute-forcing, developer attack surface, ide vulnerability management, workspace trust limitations, remote code execution, malicious package mitigation, static and dynamic analysis ## Chapters 1. **The impact of digital transformation on developer roles** (00:46) — Cloud computing transfers infrastructure and network configuration responsibilities directly to application developers. 1. **Shifting security testing left in the software cycle** (04:42) — Integrating static analysis and software composition analysis early reduces the cost of fixing vulnerabilities. 1. **Managing vulnerabilities in transitive software dependencies** (06:43) — Developers must triage and update third-party packages to prevent exploits within an application's dependency tree. 1. **Real-world examples of software supply chain attacks** (08:26) — Threat actors distribute malicious packages and exploit unpatched dependencies to compromise developer workstations and organizational networks. 1. **Visual Studio Code as a target for exploitation** (14:05) — The massive market of open-source editor extensions introduces a significant attack surface for remote code execution. 1. **Automating vulnerability research in the extension marketplace** (18:56) — A custom processing pipeline uses headless servers to dynamically analyze zipped extension archives for security flaws. 1. **Path traversal vulnerabilities in local development servers** (20:46) — Insufficient path sanitization in local preview servers exposes sensitive local files to external query manipulation. 1. **Bypassing local server CORS restrictions using cross-site scripting** (26:29) — Injecting executable payloads into a vulnerable local server circumvent browser-based cross-origin resource sharing policies. 1. **Chaining automatic browser downloads with local path traversal** (31:20) — Forcing a background file download enables an external site to execute local scripts and exfiltrate secure keys. 1. **Exploiting websocket ports to execute arbitrary commands locally** (36:31) — Bruteforcing local connection ports via image tags allows attackers to trigger external API calls from compromised extensions. 1. **Mitigating extension vulnerabilities and applying workspace trust** (41:08) — Enforcing code execution barriers and auditing third-party tools protects developer environments from persistent threats. ## Related Moments - [Risks of malicious VS Code extensions and AI assistants](https://www.wearedevelopers.com/videos/1794-wearedevelopers-live-from-javascript-to-webassembly-high-performance-charting-and-more) (from "WeAreDevelopers LIVE – From JavaScript to WebAssembly, High-Performance Charting and More") - [Introduction to VS Code security risks and threat models](https://www.wearedevelopers.com/videos/717-you-click-you-lose-a-practical-look-at-vscode-s-security) (from "You click, you lose: a practical look at VSCode's security") - [Security incidents in extension marketplaces and package managers](https://www.wearedevelopers.com/videos/1720-wearedevelopers-live-dapr-pixels-and-generative-art-open-source-and-communities-and-more) (from "WeAreDevelopers LIVE - Dapr / Pixels and Generative Art / Open Source and Communities / and more") - [Exploiting path traversal vulnerabilities in code editor extensions](https://www.wearedevelopers.com/videos/716-hack-proof-the-node-js-runtime-the-mechanics-and-defense-of-path-traversal-attacks) (from "Hack-Proof The Node.js runtime: The Mechanics and Defense of Path Traversal Attacks") - [Exploiting exposed network services in developer IDE extensions](https://www.wearedevelopers.com/videos/717-you-click-you-lose-a-practical-look-at-vscode-s-security) (from "You click, you lose: a practical look at VSCode's security") - [Targeting developer integrated development environments and plugins](https://www.wearedevelopers.com/videos/376-walking-into-the-era-of-supply-chain-risks) (from "Walking into the era of Supply Chain Risks") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [7 VSCode Extensions That Actually Make You More Efficient (2025 Edition)](https://www.wearedevelopers.com/magazine/587-7-vscode-extensions-that-actually-make-you-more-efficient-2025-edition) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 176: Expensive Agents, Taking Over VSCode and Safer Vibe Coding](https://www.wearedevelopers.com/magazine/603-dev-digest-176-expensive-agents-taking-over-vscode-and-safer-vibe-coding) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Senior Supply Chain Security Engineer](https://www.wearedevelopers.com/jobs/48462-senior-supply-chain-security-engineer) at **Docker, Inc.** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/3081075-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [SoC Offensive Security Staff Engineer](https://www.wearedevelopers.com/jobs/48479-soc-offensive-security-staff-engineer) at **Arm** - [Senior Principal Software Engineer, Docker and Ecosystem](https://www.wearedevelopers.com/jobs/48456-senior-principal-software-engineer-docker-and-ecosystem) at **Docker, Inc.** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio**