Bleepingcomputer
Malicious Extension Risks in AI-Powered VSCode Forks
First seen 5 Jan 2026, 20:31 UTC
•
•90% similarity
•22.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
AI-powered IDEs like Cursor, Windsurf, Google Antigravity, and Trae recommend extensions that do not exist in the OpenVSX registry. This allows threat actors to claim the namespace and upload malicious extensions, posing a risk to users. These IDEs, forked from Microsoft VSCode, rely on OpenVSX due to licensing restrictions preventing the use of the official store.
ThreatCluster AI