AI VS Code forks can prompt nonexistent Open VSX extensions
AI-powered VS Code forks (Cursor, Windsurf, Google Antigravity, Trae) inherit extension recommendations from Microsoft’s marketplace, but some recommended extension names don’t exist in Open VSX, the registry these forks rely on. This gaps creates a name-squatting avenue where attackers could publish malicious packages under those names; prompts can be file-based or software-based, increasing exposure.
calendar_today
2026-01-06
cursor
windsurf
open-vsx
visual-studio-code
supply-chain-security