TOPIC_NODE DIGEST_COUNT: 1

AI VS CODE FORKS CAN PROMPT NONEXISTENT OPEN VSX EXTENSIONS

calendar_today FIRST_SEEN 2026-01-06
update LAST_SYNC 2026-01-06
AI VS Code forks can prompt nonexistent Open VSX extensions
[ OVERVIEW ]

AI-powered VS Code forks (Cursor, Windsurf, Google Antigravity, Trae) inherit extension recommendations from Microsoft’s marketplace, but some recommended extension names don’t exist in Open VSX, the registry these forks rely on. This gaps creates a name-squatting avenue where attackers could publish malicious packages under those names; prompts can be file-based or software-based, increasing exposure.

[ STORY_TIMELINE ]

AI VS Code forks can prompt nonexistent Open VSX extensions

AI-powered VS Code forks (Cursor, Windsurf, Google Antigravity, Trae) inherit extension recommendations from Microsoft’s marketplace, but some recommended extension names don’t exist in Open VSX, the registry these forks rely on. This gaps creates a name-squatting avenue where attackers could publish malicious packages under those names; prompts can be file-based or software-based, increasing exposure.

article DIGEST_2026.01.06 | 2026-01-06 14:52_UTC
SUBSCRIBE_FEED
Get the digest delivered. No spam.