Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityextension-plugin-hijackidentity-authentication-vulnerabilitylateral-movement-method

Security Risks and Vulnerabilities in AI-Powered Developer Tools and Extensions

Updated 3mo agoFirst seen Jan 6, 20262 sources

Security researchers have identified significant risks in AI-powered developer tools and browser extensions, highlighting how new AI capabilities can introduce novel attack vectors. In the case of Anthropic's Claude Chrome extension, researchers at Zenity Labs demonstrated that the extension, which allows the AI to browse and interact with websites on behalf of users, can expose sensitive data and perform actions using the user's credentials. This creates opportunities for indirect prompt injection attacks, where malicious instructions embedded in web content can manipulate the AI to perform harmful actions such as deleting files or sending unauthorized messages. The extension's persistent login state and ability to access private services like Google Drive and Slack further amplify the risk, as attackers could leverage the AI's access for lateral movement within organizations.

Similarly, security concerns have been raised about AI-powered integrated development environments (IDEs) forked from Microsoft VSCode, such as Cursor and Windsurf. These IDEs recommend extensions that do not exist in the OpenVSX registry, leaving unclaimed namespaces that threat actors could exploit to distribute malicious code. Researchers from Koi Security reported that some vendors responded by removing vulnerable recommendations, but others have yet to act. These findings underscore the urgent need for both vendors and users to reassess the security implications of integrating AI into development and productivity tools, as traditional security models may not adequately address the unique risks posed by AI-driven automation and extension ecosystems.

Share:
Security Risks and Vulnerabilities in AI-Powered Developer Tools and Extensions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 5, 20266mo ago

Koi Security discloses VS Code fork extension supply-chain risk

Koi Security publicly warned that AI-powered IDEs forked from VS Code, including Cursor, Windsurf, Google Antigravity, and Trae, could expose users to malicious recommended extensions because of unclaimed OpenVSX namespaces. Koi also said it had preemptively registered some affected namespaces and uploaded placeholder extensions with Eclipse Foundation coordination to prevent abuse.

Researchers disclose Claude Chrome extension security risks

Zenity Labs reported that Anthropic's Claude Chrome extension could inherit users' authenticated web sessions and be abused through indirect prompt injection, unsafe actions, and JavaScript execution, potentially exposing sensitive data.

Jan 1, 20266mo ago

Google marks VS Code fork extension issue as fixed

Google marked the recommended-extension namespace exposure issue as resolved in its IDE after removing the affected recommendations.

Dec 26, 20256mo ago

Google removes 13 risky extension recommendations

Google removed 13 extension recommendations from its Antigravity IDE that could have mapped to unclaimed OpenVSX publisher namespaces.

Dec 18, 20256mo ago

Anthropic releases beta Claude Chrome extension

Anthropic released the beta version of its Claude Chrome extension, enabling the AI assistant to browse and interact with websites on behalf of users.

Dec 1, 20257mo ago

Cursor fixes unsafe recommended extension mappings

Cursor remediated the issue in its VS Code fork by fixing the problematic recommended extension behavior after Koi Security's disclosure.

Nov 30, 20257mo ago

Koi Security reports VS Code fork extension issue to vendors

In late November 2025, Koi Security notified Google, Windsurf, and Cursor that several VS Code-based IDEs recommended extensions that did not exist in the OpenVSX registry, creating a supply-chain takeover risk.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Affected products
2 linked
CursorPostgresql
Organizations
8 linked
Koi SecurityWindsurfCursorEclipse FoundationMicrosoft CorporationGoogleZenityAnthropic
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.