Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
leaked-secret-api-keyextension-plugin-hijackvendor-distribution-compromisethird-party-vendor-breach

VS Code Extensions Leak Sensitive Secrets, Exposing Users to Supply Chain Attacks

Updated 3mo agoFirst seen Oct 16, 20253 sources

Researchers discovered that over 550 sensitive secrets were inadvertently leaked through more than 500 Visual Studio Code (VS Code) extensions available on both the VS Code and Open VSX marketplaces. These secrets included access and authorization tokens, credentials, API keys, encryption keys, and certificates, which are critical for securing access to various platforms and services. The investigation, conducted by Wiz Security, revealed that the leaked secrets spanned 67 categories, with the majority falling into three main groups: generative AI platforms, high-risk professional platforms such as AWS, GCP, Auth0, and GitHub, and databases like MongoDB and Postgres. Notably, more than 100 of the exposed secrets would have allowed attackers to update the affected extensions themselves. Because VS Code automatically updates extensions, this created a significant risk that attackers could deploy malicious updates to a large user base without user intervention. Wiz Security estimated that, had these vulnerabilities been exploited, malware could have been pushed to approximately 150,000 users in a single attack. The risk was not limited to code-heavy extensions; even theme extensions, which are often perceived as harmless, were found to be capable of introducing malware. The research highlighted that some internal extensions, such as those published by large corporations for internal use, were inadvertently made public, further increasing the attack surface. Vendor-specific extensions, commonly used for convenience, were identified as particularly attractive targets for attackers due to their potential for targeted exploitation. Microsoft was notified of the findings and worked with the researchers to address the issues and mitigate the risks. The incident underscores the importance of rigorous security practices in extension development and the need for continuous monitoring of third-party code in software supply chains. The exposure of secrets in widely used development tools like VS Code demonstrates how supply chain vulnerabilities can have far-reaching consequences. Organizations are advised to audit their use of extensions, restrict unnecessary permissions, and ensure that sensitive credentials are never hardcoded or exposed in public repositories. The case also serves as a warning about the risks of publishing internal tools to public marketplaces, as this can inadvertently expose sensitive infrastructure to external threats. The findings have prompted calls for improved vetting processes for extensions and greater awareness among developers about the risks of credential leakage. This incident is a stark reminder that even seemingly minor oversights in software development can lead to large-scale security incidents affecting tens of thousands of users. The potential for automated malware deployment through compromised extensions highlights the evolving nature of supply chain threats in the software ecosystem. Security researchers continue to monitor the situation and recommend best practices for extension security to prevent similar incidents in the future.

Share:
VS Code Extensions Leak Sensitive Secrets, Exposing Users to Supply Chain Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Oct 15, 20258mo ago

Microsoft revokes tokens and adds marketplace protections

Following the disclosures, Microsoft revoked compromised tokens, scanned existing extensions, and implemented new security measures in its marketplace. Coverage indicates the Eclipse Foundation's response for Open VSX was not clearly established at the time of reporting.

Researchers identify 550+ leaked secrets in VS Code extension marketplaces

Wiz discovered more than 550 unique secrets, including access tokens and API keys, exposed in extensions published to Microsoft's VS Code Marketplace and the Open VSX Registry. The leaked credentials affected services such as Azure DevOps, AWS, Google Cloud, and AI providers, creating supply-chain risk for more than 100,000 users.

Apr 1, 20251y ago

Additional disclosures to Microsoft continue

Dark Reading says Wiz also reported related findings to Microsoft in April 2025, indicating continued coordinated disclosure as the scope of exposed secrets became clearer.

Mar 1, 20251y ago

Wiz reports exposed secrets in VS Code extensions to Microsoft

According to Dark Reading, Wiz disclosed the issue to Microsoft in March 2025 after finding hardcoded credentials in publicly available VS Code extensions. The report concerned secrets exposed through extensions in the VS Code software supply chain.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Organizations
17 linked
Microsoft CorporationHugging FaceAuth0Amazon Web ServicesDeepseekMongodbAnthropicPostgresqlSupabaseOpenaiPerplexityStripeEclipse FoundationGitHubWizxAIGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.