Microsoft Visual Studio Marketplace is a organization tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity January 5, 2026.
Microsoft Visual Studio Marketplace is Microsoft's official extension marketplace for Visual Studio and Visual Studio Code ecosystems. It serves as a central distribution channel for third-party extensions and has become a notable attack surface for extension- and supply-chain–based threats, evidenced by reports of malicious packages and compromised forks targeting the platform.
A fourth wave of the GlassWorm campaign is targeting macOS developers by distributing malicious VSCode/OpenVSX extensions that contain trojanized versions of crypto wallet applications. These extensions are available in…
The Open VSX registry faced a supply chain attack after access tokens were leaked, allowing threat actors to publish malicious extensions. The GlassWorm malware campaign has returned with new extensions targeting…
AI-powered IDEs like Cursor, Windsurf, Google Antigravity, and Trae recommend extensions that do not exist in the OpenVSX registry. This allows threat actors to claim the namespace and upload malicious extensions,…