The VSCode Marketplace is pretty easy to hack with malicious extensions


VSCode Marketplace, a repository for Visual Studio Code (VSC) externsions, has poor security defenses, allowing threat actors to abuse it and distribute malicious code among the millions of its users, experts have warned.
A report from AquaSec tested the platform and concluded that abusing it to distribute malware (opens in new tab) was ridiculously easy.
Furthermore, the researchers claim they weren’t the first to spot the flaws – some threat actors were already active.
Spoofing important details
In a blog post (opens in new tab), AquaSec’s team outlined how it tried to upload a typosquatted, malicious version of a popular extension with 27 million downloads.
It realized that the malware needed not even be typosquatted – the platform has a feature called ‘displayName’ allowing the authors to name their extensions however they like – the name does not need to be unique. So, they named it exactly the same as the legitimate one.
Then, they realized that they could also use the same logo and description as the legitimate project.
Also, the details, while they get pulled from GitHub, can later be edited. That means that the attackers can easily spoof the project details and present the malware as a legitimate tool with a long development history. The only thing that couldn’t be spoofed was the number of downloads and the search ranking.
“However, over time an increasing pool of unknowing users will have downloaded our faux extension. As these figures grow, the extension will gain credibility,” AquaSec said. “Additionally, since in the dark web it is possible to purchase various services, an extremely determined attacker could potentially manipulate these numbers by buying services which would inflate the number of downloads and stars.”
AquaSec also looked at the verification badge on VSCode Marketplace and concluded that the feature is meaningless, as any published with a purchased domain gets one, regardless of the relevance of the domain to the software project.
While the researchers only made a proof-of-concept, they also found actual malicious code lurking in the store. These are named “API Generator Plugin” and “code tester”.
Visual Studio Code is Microsoft’s source-code editor, used by some 70% of professional software developers worldwide, according to BleepingComputer. The extensions can be used to install additional programs, steal source code, or tamper with it in other ways in the VSCode IDE.
Via: BleepingComputer (opens in new tab)
Audio player loading… VSCode Marketplace, a repository for Visual Studio Code (VSC) externsions, has poor security defenses, allowing threat actors to abuse it and distribute malicious code among the millions of its users, experts have warned. A report from AquaSec tested the platform and concluded that abusing it to distribute…
Recent Posts
- All of Chipolo’s Bluetooth trackers are discounted in sitewide sale
- Fortnite: Lawless gets first trailer highlighting the new season’s battle pass roster and the chaos of Crime City
- Chase will start blocking Zelle payments over social media
- Fortnite is adding Sub-Zero next season, finally becoming the first game where Street Fighter vs Mortal Kombat is possible
- Yay, you can now use AMD’s fastest ever GPU – AMD’s Instinct MI325X AI accelerator has 256GB memory and can run Crysis (sort of)
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010