VSCode is a technology platform tracked across 10 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed January 5, 2026; most recent activity June 4, 2026.
VSCode is a popular code editor/IDE with an extensible marketplace, and its forks likewise offer expansion ecosystems. Recent reports describe threat actors abusing the IDEs’ 'recommended extensions' mechanism to push malicious apps to developers, turning development tools into infection vectors. This is significant for cybersecurity due to supply-chain risk and targeted developer-focused malware campaigns across IDE ecosystems.
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
A newly disclosed zero-day vulnerability in Visual Studio Code (VS Code) enables attackers to steal GitHub OAuth tokens by tricking users into clicking a malicious link. The flaw exploits the webview message-passing…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
On April 1, 2026, Drift Protocol, a decentralized exchange on the Solana blockchain, confirmed it was under an active attack, resulting in an estimated loss of $270 million to $285 million. The exploit involved…
A newly discovered vulnerability, CVE-2026-6770, allows attackers to fingerprint users of Firefox and Tor browsers, even in Private Browsing mode. The flaw, identified in the IndexedDB API, enables the creation of a…
The North Korea-linked hacking group WaterPlum has launched a new malware strain called StoatWaffle, targeting developers through compromised Visual Studio Code (VSCode) repositories. This malware is part of an ongoing…
AI-powered IDEs like Cursor, Windsurf, Google Antigravity, and Trae recommend extensions that do not exist in the OpenVSX registry. This allows threat actors to claim the namespace and upload malicious extensions,…
A security flaw in AI-powered development environments Cursor, Windsurf, and Google Antigravity has exposed millions of developers to potential malware. These IDEs, which have over a million users combined, were found…