VSCode — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
January 5, 2026
Last Seen
June 4, 2026

VSCode is a technology platform tracked across 10 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed January 5, 2026; most recent activity June 4, 2026.

Overview

VSCode is a popular code editor/IDE with an extensible marketplace, and its forks likewise offer expansion ecosystems. Recent reports describe threat actors abusing the IDEs’ 'recommended extensions' mechanism to push malicious apps to developers, turning development tools into infection vectors. This is significant for cybersecurity due to supply-chain risk and targeted developer-focused malware campaigns across IDE ecosystems.

Related Threat Clusters

  • Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack

    Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…

    15 articles · Updated May 11, 2026
  • Checkmarx Data Leak Linked to Supply-Chain Attack by TeamPCP

    Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…

    12 articles · Updated April 27, 2026
  • Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google

    The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…

    30 articles · Updated May 27, 2026
  • Zero-Day Vulnerability in VS Code Allows GitHub Token Theft via Malicious Links

    A newly disclosed zero-day vulnerability in Visual Studio Code (VS Code) enables attackers to steal GitHub OAuth tokens by tricking users into clicking a malicious link. The flaw exploits the webview message-passing…

    14 articles · Updated June 3, 2026
  • GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension

    On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…

    149 articles · Updated May 20, 2026
  • Drift Protocol Suffers Major $270M Exploit Amid Ongoing Investigation

    On April 1, 2026, Drift Protocol, a decentralized exchange on the Solana blockchain, confirmed it was under an active attack, resulting in an estimated loss of $270 million to $285 million. The exploit involved…

    123 articles · Updated April 1, 2026
  • Firefox Bug CVE-2026-6770 Allows Tracking of Tor Users

    A newly discovered vulnerability, CVE-2026-6770, allows attackers to fingerprint users of Firefox and Tor browsers, even in Private Browsing mode. The flaw, identified in the IndexedDB API, enables the creation of a…

    3 articles · Updated April 27, 2026
  • WaterPlum's StoatWaffle Malware Targets VSCode Users

    The North Korea-linked hacking group WaterPlum has launched a new malware strain called StoatWaffle, targeting developers through compromised Visual Studio Code (VSCode) repositories. This malware is part of an ongoing…

    4 articles · Updated March 19, 2026
  • Malicious Extension Risks in AI-Powered VSCode Forks

    AI-powered IDEs like Cursor, Windsurf, Google Antigravity, and Trae recommend extensions that do not exist in the OpenVSX registry. This allows threat actors to claim the namespace and upload malicious extensions,…

    3 articles · Updated January 5, 2026
  • Malicious App Extensions Recommended by Popular AI IDEs

    A security flaw in AI-powered development environments Cursor, Windsurf, and Google Antigravity has exposed millions of developers to potential malware. These IDEs, which have over a million users combined, were found…

    2 articles · Updated January 6, 2026

Recent Intelligence Reports

  • Hole in GitHub’s browser — Csoonline · June 4, 2026
  • Glassworm botnet that targeted OS devs smashed to pieces — Computerweekly · May 27, 2026
  • GitHub hit by a compromised VSCode extension — Reddit · May 20, 2026
  • Official CheckMarx Jenkins package compromised with infostealer — Bleepingcomputer · May 11, 2026
  • Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data — Bleepingcomputer · April 28, 2026
  • Risky Bulletin: New fingerprinting technique can track Tor users — News.Risky.Biz · April 27, 2026
  • Suspected North Korean-Linked Organization Planned Infiltration for Six Months — Bitget · April 5, 2026
  • WaterPlum Unleashes “StoatWaffle” Malware in VSCode Supply Chain Attack — Gbhackers · March 19, 2026

CVSS v3.1 Breakdown