terminal
howtonotcode.com
topic Topic
Appeared in 1 digest

AI VS Code forks can prompt nonexistent Open VSX extensions

calendar_today First seen: 2026-01-06
update Last updated: 2026-01-06
AI VS Code forks can prompt nonexistent Open VSX extensions

Overview

AI-powered VS Code forks (Cursor, Windsurf, Google Antigravity, Trae) inherit extension recommendations from Microsoft’s marketplace, but some recommended extension names don’t exist in Open VSX, the registry these forks rely on. This gaps creates a name-squatting avenue where attackers could publish malicious packages under those names; prompts can be file-based or software-based, increasing exposure.

Story Timeline

AI VS Code forks can prompt nonexistent Open VSX extensions

AI-powered VS Code forks (Cursor, Windsurf, Google Antigravity, Trae) inherit extension recommendations from Microsoft’s marketplace, but some recommended extension names don’t exist in Open VSX, the registry these forks rely on. This gaps creates a name-squatting avenue where attackers could publish malicious packages under those names; prompts can be file-based or software-based, increasing exposure.

article 2026-01-06 2026-01-06 14:52