Security Risks and Vulnerabilities in AI-Powered Developer Tools and Extensions
Security researchers have identified significant risks in AI-powered developer tools and browser extensions, highlighting how new AI capabilities can introduce novel attack vectors. In the case of Anthropic's Claude Chrome extension, researchers at Zenity Labs demonstrated that the extension, which allows the AI to browse and interact with websites on behalf of users, can expose sensitive data and perform actions using the user's credentials. This creates opportunities for indirect prompt injection attacks, where malicious instructions embedded in web content can manipulate the AI to perform harmful actions such as deleting files or sending unauthorized messages. The extension's persistent login state and ability to access private services like Google Drive and Slack further amplify the risk, as attackers could leverage the AI's access for lateral movement within organizations.
Similarly, security concerns have been raised about AI-powered integrated development environments (IDEs) forked from Microsoft VSCode, such as Cursor and Windsurf. These IDEs recommend extensions that do not exist in the OpenVSX registry, leaving unclaimed namespaces that threat actors could exploit to distribute malicious code. Researchers from Koi Security reported that some vendors responded by removing vulnerable recommendations, but others have yet to act. These findings underscore the urgent need for both vendors and users to reassess the security implications of integrating AI into development and productivity tools, as traditional security models may not adequately address the unique risks posed by AI-driven automation and extension ecosystems.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
7 events from the most recent confirmed update back to the earliest known activity.
Koi Security discloses VS Code fork extension supply-chain risk
Koi Security publicly warned that AI-powered IDEs forked from VS Code, including Cursor, Windsurf, Google Antigravity, and Trae, could expose users to malicious recommended extensions because of unclaimed OpenVSX namespaces. Koi also said it had preemptively registered some affected namespaces and uploaded placeholder extensions with Eclipse Foundation coordination to prevent abuse.
Researchers disclose Claude Chrome extension security risks
Zenity Labs reported that Anthropic's Claude Chrome extension could inherit users' authenticated web sessions and be abused through indirect prompt injection, unsafe actions, and JavaScript execution, potentially exposing sensitive data.
Google marks VS Code fork extension issue as fixed
Google marked the recommended-extension namespace exposure issue as resolved in its IDE after removing the affected recommendations.
Google removes 13 risky extension recommendations
Google removed 13 extension recommendations from its Antigravity IDE that could have mapped to unclaimed OpenVSX publisher namespaces.
Anthropic releases beta Claude Chrome extension
Anthropic released the beta version of its Claude Chrome extension, enabling the AI assistant to browse and interact with websites on behalf of users.
Cursor fixes unsafe recommended extension mappings
Cursor remediated the issue in its VS Code fork by fixing the problematic recommended extension behavior after Koi Security's disclosure.
Koi Security reports VS Code fork extension issue to vendors
In late November 2025, Koi Security notified Google, Windsurf, and Cursor that several VS Code-based IDEs recommended extensions that did not exist in the OpenVSX registry, creating a supply-chain takeover risk.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


