Malicious Extension Risks in AI-Powered VSCode Forks

Malicious Extension Risks in AI-Powered VSCode Forks

First seen 5 Jan 2026, 20:31 UTC BleepingcomputerScworld 90% similarity 22.3

Article Content

Browse articles
ThreatCluster

AI-powered IDEs like Cursor, Windsurf, Google Antigravity, and Trae recommend extensions that do not exist in the OpenVSX registry. This allows threat actors to claim the namespace and upload malicious extensions, posing a risk to users. These IDEs, forked from Microsoft VSCode, rely on OpenVSX due to licensing restrictions preventing the use of the official store.

ThreatCluster AI

Community

Browse all →