By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX
Computing

VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX

News Room
Last updated: 2026/01/06 at 8:09 AM
News Room Published 6 January 2026
Share
VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX
SHARE

Jan 06, 2026Ravie LakshmananThreat Intelligence / Cloud Security

Popular artificial intelligence (AI)-powered Microsoft Visual Studio Code (VS Code) forks such as Cursor, Windsurf, Google Antigravity, and Trae have been found to recommend extensions that are non-existent in the Open VSX registry, potentially opening the door to supply chain risks when bad actors publish malicious packages under those names.

The problem, according to Koi, is that these integrated development environments (IDEs) inherit the list of officially recommended extensions from Microsoft’s extensions marketplace. These extensions don’t exist in Open VSX.

The VS Code extension recommendations can take two different forms: file-based, which are displayed as toast notifications when users open a file in specific formats, or software-based, which are suggested when certain programs are already installed on the host.

“The problem: these recommended extensions didn’t exist on Open VSX,” Koi security researcher Oren Yomtov said. “The namespaces were unclaimed. Anyone could register them and upload whatever they wanted.”

Cybersecurity

In other words, an attacker could weaponize the absence of these VS Code extensions and the fact that the AI-powered IDEs are VS Code forks to upload a malicious extension to the Open VSX registry, such as ms-ossdata.vscode-postgresql.

As a result, any time a developer with PostgreSQL installed opens one of the aforementioned IDEs and sees the message “Recommended: PostgreSQL extension,” a trivial install action is enough to result in the deployment of the rogue extension on their system instead.

This simple act of trust can have severe consequences, potentially leading to the theft of sensitive data, including credentials, secrets, and source code. Koi said its placeholder PostgreSQL extension attracted no less than 500 installs, indicating that developers are downloading it simply because the IDE suggested it as a recommendation.

The names of some of the extensions that have been claimed by Koi with a placeholder are listed below –

  • ms-ossdata.vscode-postgresql
  • ms-azure-devops.azure-pipelines
  • msazurermtools.azurerm-vscode-tools
  • usqlextpublisher.usql-vscode-ext
  • cake-build.cake-vscode
  • pkosta2005.heroku-command
Cybersecurity

In response to responsible disclosure, Cursor and Google have rolled out fixes to address the issue. The Eclipse Foundation, which oversees Open VSX, has since removed non-official contributors and enforced broader registry-level safeguards.

With threat actors increasingly focusing on exploiting the security gaps in extension marketplaces and open-source repositories, it’s essential that developers exercise caution prior to downloading any packages or approving installs by verifying they come from a trusted publisher.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Best AirPods 4 deal: Save  at Amazon Best AirPods 4 deal: Save $30 at Amazon
Next Article The Best Ventless Fireplaces if You Can’t Have a Chimney The Best Ventless Fireplaces if You Can’t Have a Chimney
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The Costco Camera Bundle Every Photographer Should Know About – BGR
The Costco Camera Bundle Every Photographer Should Know About – BGR
News
“There’s a lot of smart home gadgets you don’t want to see, and we make them more integrated and fun” — IKEA design expert shares the key to the company’s success
“There’s a lot of smart home gadgets you don’t want to see, and we make them more integrated and fun” — IKEA design expert shares the key to the company’s success
News
ASML will lay off 1,700 workers despite its good results
ASML will lay off 1,700 workers despite its good results
Mobile
Apps are going missing from Google’s Nest Hub displays
Apps are going missing from Google’s Nest Hub displays
News

You Might also Like

Amazon asks FCC for 2-year extension in Leo satellite deployment deadline, citing a rocket shortage
Computing

Amazon asks FCC for 2-year extension in Leo satellite deployment deadline, citing a rocket shortage

5 Min Read
BingX AI Bingo Integrates TradFi Suite to Expand Intelligent, Multi-Asset Trading | HackerNoon
Computing

BingX AI Bingo Integrates TradFi Suite to Expand Intelligent, Multi-Asset Trading | HackerNoon

3 Min Read
The future of AGI should not come at the expense of our planet · TechNode
Computing

The future of AGI should not come at the expense of our planet · TechNode

9 Min Read
FIMI launches Mini 3 drone featuring Sony 48MP sensor and 249g weight · TechNode
Computing

FIMI launches Mini 3 drone featuring Sony 48MP sensor and 249g weight · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?