🔧 AI Nachrichten Debian is Voting on Whether to Allow AI-Assisted Contributions(23.08.2026 um 09:34 Uhr)
🔧 AI Nachrichten The Linux Kernel Is Approaching 2,000 CVEs Per Release(29.08.2026 um 20:00 Uhr)
⚠️ Malware / Trojaner / VirenCitrix Adds a Linux-Powered Escape Hatch For Compromised Windows PCs(30.08.2026 um 17:34 Uhr)
🔧 AI Nachrichten Debian is Voting on Whether to Allow AI-Assisted Contributions(23.08.2026 um 09:34 Uhr)
🔧 AI Nachrichten The Linux Kernel Is Approaching 2,000 CVEs Per Release(29.08.2026 um 20:00 Uhr)
⚠️ Malware / Trojaner / VirenCitrix Adds a Linux-Powered Escape Hatch For Compromised Windows PCs(30.08.2026 um 17:34 Uhr)

🔧 Programmierung 🕛 vor 2 Monaten 6 Min Lesezeit
0

How to Actually Check if a VS Code Extension is Safe Before You Install It

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

You're about to install a VS Code extension. Maybe it's a formatter, a linter, a theme, an AI tool. You search, you find it, it has decent reviews. You click Install.



But here's what you probably didn't check — and what almost nobody does.









What VS Code Extensions Can Actually Do



Before we get into how to evaluate one, it's worth being clear about what you're giving permission for. VS Code extensions run with full access to:





  • Your filesystem — read, write, delete


  • Your environment variables — including secrets, tokens, and credentials your shell exposes


  • Network connections — outbound requests to anywhere


  • Child processes — spawning terminals, shell commands, background workers


  • Other extensions — via the extension API
    There is no sandbox. When you install an extension, you're running code with your own user permissions. The same permissions that can push to your git repos, read your .env files, and access your SSH keys.



This isn't hypothetical. Extensions with millions of installs have been caught doing exactly these things.









The Checklist Most Developers Skip



Here's what a 60-second review actually looks like:






1. Look at the publisher, not just the extension name



Anyone can publish to the VS Code Marketplace. The publisher ID is the only stable identifier — the display name can be anything, and typosquatting is real.




  • Is the publisher verified (blue checkmark)?

  • Does the publisher have other extensions, a website, a GitHub presence?

  • Does the publisher name look like a real organization or a random string?
    Legitimate extensions from major companies (Microsoft, Prettier, ESLint) will have recognizable, verified publishers. A one-off extension with a publisher ID like devtools-pro-2024 is worth extra scrutiny.






2. Check when it was last updated



An extension that hasn't been touched in 2+ years is a supply chain risk waiting to happen. Old dependencies, unmaintained code, and abandoned repos are exactly how attackers get in — either by compromising the account or injecting into a dependency.



Look at the "Last Updated" date on the Marketplace listing. Then open the GitHub repo (if it exists) and check the actual commit history. Sometimes the Marketplace listing shows a recent publish date that just reflects an automated re-publish, not real maintenance.






3. Look at the package.json permissions before installing



Every extension declares what it can do in its package.json. You can find this in the source repo. Look for:





  • activationEvents — when does this extension activate? * means it runs on every file you open.


  • contributes.commands — what commands does it register?

  • Any explicit permission requests
    An extension that activates on * and makes network calls is doing something the moment you open VS Code, before you've even used it.






4. Grep the source for network calls



This takes 2 minutes if there's a public repo. Clone it or browse it on GitHub and look for:




CODE
fetch(
axios
http.request
https.request
xhr
WebSocket






Are those calls going to localhost, or to an external server? What data is in the request body? A linter that phones home is a red flag. A language server that connects to a known service is expected.






5. Check the dependencies



The extension's own code might be clean. Its dependencies might not be. Look at the package.json for third-party packages, then check them against known vulnerability databases. A single compromised npm package can turn a legitimate extension malicious overnight — this is exactly how supply chain attacks work.



This is tedious to do manually. Tools like or check the dependency list manually

  • Look at what events trigger activation
    Every quarter or so, do a pass over your installed extensions:




  • CODE
    # List all installed extensions
    code --list-extensions






    For anything you don't recognize or haven't used recently: uninstall first, reinstall if you actually need it.









    Why This Matters More Than It Used to



    A year ago, the threat model for developer tools was mostly theoretical. It's not anymore.



    We've seen self-propagating worms targeting VS Code extensions. We've seen extensions with millions of downloads caught harvesting credentials. Microsoft's own telemetry has flagged thousands of extensions with suspicious behaviors.



    The attack surface is your entire development environment — your code, your credentials, your git history, your cloud provider tokens. Developers are high-value targets precisely because of what they have access to.



    The VS Code Marketplace is not curated the way the iOS App Store is. It's closer to npm: anyone can publish, automated scanning catches some things but not everything, and you're largely responsible for what you run.



    That's not a reason to avoid extensions. It's a reason to take 60 seconds before you click Install.






    Check your extensions at vscan.dev

    Vollständiger Original-Bericht
    Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
    ↗ Original-Artikel auf dev.to lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    1 Quelle
    Debian is Voting on Whether to Allow AI-Assisted Contributions
    1 Quelle
    The Linux Kernel Is Approaching 2,000 CVEs Per Release
    1 Quelle
    Citrix Adds a Linux-Powered Escape Hatch For Compromised Windows PCs
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten How to Actually Check if a VS Code Extension is Safe Before You Install It

    Thematisch verwandte Begriffe: Actually, Check, Code, Extension · 6 Treffer

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...