Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Researchers Identify Security Risks in VS Code Marketplace
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Researchers Identify Security Risks in VS Code Marketplace

Highlights

  • Researchers found security vulnerabilities in the VS Code Marketplace.

  • Extensions can execute any action without user permission.

  • Verification and trending algorithms are easily manipulated.

Samantha Reed
Last updated: 10 June, 2024 - 1:45 pm 1:45 pm
Samantha Reed 11 months ago
Share
SHARE

The VS Code Marketplace faces scrutiny as researchers have uncovered significant security vulnerabilities. These flaws allow extensions with malicious dependencies to gain high install numbers, thereby gaining credibility and potentially compromising users’ systems. The study emphasizes the necessity of stricter security protocols to safeguard users from potential attacks.

Contents
Security ConcernsTrending Algorithm Manipulation

The Visual Studio Code (VSCode) Marketplace is a platform for developers to share and download extensions, enhancing the functionalities of the VSCode editor. Launched by Microsoft in 2015, it allows users to customize their coding environment by adding features such as debuggers, themes, and programming language support. The marketplace has grown significantly in popularity due to its extensive library of extensions and ease of use.

Researchers found that some extensions were communicating with suspicious addresses and executing unknown binaries. This discovery underscores the need for an improved security framework in the VS Code Marketplace. They also highlighted the absence of a permission system, which allows any extension to perform any action, creating substantial security risks. A seemingly harmless theme extension, for example, could execute code or access files without the user’s knowledge.

Security Concerns

Unlike browser extensions or add-ins, VSCode extensions have unrestricted access to the host machine. This access allows them to execute system calls, spawn child processes, and import NodeJS packages. The ability for extensions to interact with the OS in various ways makes it impossible for VSCode to regulate their behavior. Thus, traditional security tools designed to detect suspicious activity are ineffective because legitimate VSCode functionality inherently involves reading files, executing commands, and creating child processes.

Another issue arises from the security vulnerability found in the Visual Studio Code Marketplace, where researchers discovered that anyone could become a verified publisher by adding a cheap domain to their account. This verification process, intended to signify trustworthy extensions, only requires a $5 domain name, granting attackers the credibility to distribute malicious extensions.

Trending Algorithm Manipulation

The trending algorithm in the marketplace prioritizes extensions with low install numbers. By repeatedly installing the extension, attackers can manipulate the rankings to gain exposure to developers. Additionally, design flaws in Visual Studio Code extensions allow malicious extensions to steal authentication tokens and perform arbitrary code execution.

– Extensions have unrestricted access to execute system calls and create child processes.
– Verified publisher status can be easily manipulated with a cheap domain.
– The trending algorithm can be exploited to increase the visibility of malicious extensions.

To address these concerns, Amit Assaraf recommends that Microsoft implement permission models and restrictions on extensions. The current lack of manageability in VS Code makes it difficult for organizations to assess and govern extensions, highlighting the need for improved security controls.

The study reveals significant security risks in the VS Code Marketplace, necessitating immediate attention and action. Introducing permission models and imposing restrictions on extensions could mitigate these issues. Improving the verification process and trending algorithm will further shield users from potential threats. The findings advocate for a more robust security framework within the VS Code Marketplace to ensure user safety and maintain the integrity of the platform.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Massachusetts Student Admits Guilt in Massive School Data Breach

Telecom Breach Leaves Executives Stunned as Government Faces Backlash

House Bill Proposes Overhaul for Federal Cyber Workforce Training

CIOs Tackle Quantum Threat in Encryption Race

FTC Seeks New Tools to Combat Deepfake Pornography

Share This Article
Facebook Twitter Copy Link Print
Samantha Reed
By Samantha Reed
Samantha Reed is a 40-year-old, New York-based technology and popular science editor with a degree in journalism. After beginning her career at various media outlets, her passion and area of expertise led her to a significant position at Newslinker. Specializing in tracking the latest developments in the world of technology and science, Samantha excels at presenting complex subjects in a clear and understandable manner to her readers. Through her work at Newslinker, she enlightens a knowledge-thirsty audience, highlighting the role of technology and science in our lives.
Previous Article Safe Affine Formation Using Terminal Sliding Mode Control with Input Constraints
Next Article Microsoft Invites iOS Users To Test New 365 Features

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Sam Altman Backs Retro Biosciences for Life-Extending Therapies
Technology
TRON1 Robot Expands Capabilities with New Features
Robotics
Simbe Robots Boost Retail Efficiency with AI Innovations
Robotics
Tesla Prepares Massive Robotaxi Rollout in Austin
Electric Vehicle
Orbit 5.0 Powers Up Boston Dynamics’ Spot Robots
Robotics
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?