Researchers reported a Visual Studio Code Workspace Trust and Restricted Mode bypass in which a malicious repository can use a crafted command: link to invoke the internal workbench.extensions.installExtension command. If a developer Ctrl-clicks the link in VS Code’s raw source editor, the chain can install a local malicious .vsix package, activate it immediately, and persist across subsequent VS Code launches; the reported issue is that local VSIX packages are accepted without signature or publisher validation.
A malicious extension can execute JavaScript or TypeScript with the logged-in user’s privileges, putting developer files, credentials, and software-delivery infrastructure at risk. Organizations should keep Workspace Trust enabled, instruct developers not to open links in unfamiliar repositories, review installed extensions, and centrally restrict extension installation where possible. Disabling editor link detection with "editor.links": false is a temporary mitigation while command-link handling and extension-install controls are assessed.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Remedio researchers reported that a crafted `command:` link in a malicious Visual Studio Code project can invoke `workbench.extensions.installExtension` to install a local malicious VSIX package. The extension can activate immediately and persist across later VS Code sessions, potentially running with the logged-in user's permissions despite the workspace being untrusted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.