VS Code Marketplace is a platform for distributing Visual Studio Code extensions.
Overview
VS Code Marketplace is a platform for distributing Visual Studio Code extensions. Recent reports show malicious activity targeting the marketplace, including deceptive extensions masquerading as PNG files and a ransomware-like campaign named 'Ransomvibing,' highlighting significant supply-chain and developer-machine risk within extension ecosystems.
Related Threat Clusters
-
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
Critical Vulnerability in Claude Code GitHub Actions Exposes Repositories to Attacks
A critical supply chain vulnerability in Claude Code’s GitHub Actions, identified by security researcher Ryota K from GMO Flat Security, allows attackers to compromise any repository using Anthropic’s CI/CD workflow.…
18 articles · Updated June 2, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
743 articles · Updated April 29, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
GitHub Breach Linked to Compromised Nx Console Extension
On May 19, 2026, GitHub announced an investigation into unauthorized access to internal repositories after a malicious Visual Studio Code extension was executed on an employee's device. The attack, attributed to the…
5 articles · Updated July 7, 2026 -
19 Malicious VS Code Extensions Disguised as PNG Files Detected
ReversingLabs identified 19 malicious Visual Studio Code extensions that conceal trojans within fake PNG files. Developers using these extensions are at risk of malware infection through a popular dependency. The…
2 articles · Updated December 11, 2025 -
Malware Campaign Targets Open VSX Extension with 5,066 Downloads
A sophisticated malware campaign has compromised the Open VSX extension marketplace, affecting over 5,000 developer workstations. The malicious package masqueraded as a legitimate Angular Language Service extension,…
20 articles · Updated January 30, 2026 -
Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace
A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in extensions on Microsoft's Visual Studio Code marketplace. The malicious extension, named susvsex, was published by an unknown actor and…
1 article · Updated November 7, 2025 -
Ransomvibe Ransomware Discovered in VS Code Extensions
A strain of ransomware behavior, referred to as Ransomvibe, has been embedded in Visual Studio Code extensions. The malicious extension, named susvsex, was published by an actor identified as 'suspublisher18' and openly…
3 articles · Updated November 7, 2025
Recent Intelligence Reports
- Link — edge.prnewswire.com · July 8, 2026
- Snyk researcher Stephen Thoemmes — snyk.io · July 2, 2026
- AI Coding Agents Skip Package Verification, and Attackers Are Exploiting It — Techtimes · July 1, 2026
- GitHub faces a fight for its survival at Microsoft — Theverge · May 21, 2026
- GitHub breached via poisoned VS Code extension, 3,800 repos stolen — Thenextweb · May 20, 2026
- GitHub Breached via VS Code Extension — Aikido.Dev · May 20, 2026
- Ongoing Security Updates — checkmarx.com · May 11, 2026
- Dangerous new malware targets macOS devices via OpenVSX extensions — Msn · February 7, 2026