GLOBAL SITUATIONMONITORING
517 published briefsUTCThu, May 14 19:57:10
VSCode fork extension attack
Forked VSCode IDEs recommending non-existent OpenVSX extensions create a namespace hijack supply-chain risk.
1 intelligence brief← Intelligence Hub
-

VSCode fork extension attack: hijacked recommendations
AI-powered VSCode forks still recommend extensions missing in OpenVSX, letting attackers hijack namespaces and ship malware—here’s how to lock it down.