Visual Studio Marketplace is the extension platform for Visual Studio Code and Visual Studio, enabling discovery and installation of thousands of third-party extensions.
Visual Studio Marketplace is a technology platform tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 17, 2025; most recent activity May 20, 2026.
Visual Studio Marketplace is the extension platform for Visual Studio Code and Visual Studio, enabling discovery and installation of thousands of third-party extensions. Its openness and reliance on recommended extensions create a cybersecurity surface: attackers can influence extension recommendations or exploit forked IDE distributions to push malicious tooling, underscoring the importance of provenance, signing, and vetting of extensions.
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
Keeper Security has launched new extensions for JetBrains and Visual Studio Code that integrate secure secrets management directly into development environments. This initiative aims to prevent the leakage of sensitive…
AI-powered IDEs like Cursor, Windsurf, Google Antigravity, and Trae recommend extensions that do not exist in the OpenVSX registry. This allows threat actors to claim the namespace and upload malicious extensions,…
Visual Studio Marketplace is the extension platform for Visual Studio Code and Visual Studio, enabling discovery and installation of thousands of third-party extensions.
The most recent intelligence report mentioning Visual Studio Marketplace on ThreatCluster is dated May 20, 2026. Activity was first observed November 17, 2025, giving a tracked span from then to May 20, 2026.
Across ThreatCluster reporting, Visual Studio Marketplace most frequently co-occurs with Supply Chain Attack, Azure, Cursor, Koi, OpenVSX, among 12 tracked related entities.
The most significant recent cluster is “GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension” (149 articles · Updated May 20, 2026). Visual Studio Marketplace appears across 3 threat clusters in total, listed above with sources.
Visual Studio Marketplace appears in 3 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.