GitHub Codespaces and VS Code Extension Ecosystem Targeted in Developer Supply-Chain Attacks
Security researchers reported multiple attack paths in GitHub Codespaces where opening a malicious repository or pull request can trigger remote code execution (RCE) by abusing repository-controlled VS Code configuration that Codespaces automatically honors (e.g., .vscode/ and .devcontainer/). The described impact includes arbitrary command execution inside the Codespace, exfiltration of GitHub tokens and secrets, and abuse of hidden APIs to access premium Copilot models—highlighting developer environments as a high-value supply-chain entry point because they often contain credentials outside centralized secret management.
In parallel, the Eclipse Foundation announced it will mandate pre-publish security checks for extensions uploaded to the Open VSX Registry to reduce supply-chain risk from malicious or compromised extensions. The planned controls aim to detect and quarantine suspicious uploads (e.g., namespace/name impersonation, accidentally published secrets, and known malicious patterns) before they are publicly available, following a trend of increased attacks on extension/package ecosystems (including recent cases where a compromised publisher account was used to ship poisoned updates).

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Open VSX plans enforcement of pre-publication checks
After the February monitoring phase, the Eclipse Foundation said enforcement of the new pre-publication security checks for Open VSX extensions would begin the following month.
Open VSX begins monitoring-only rollout of extension screening
The Eclipse Foundation said February 2026 would be used to monitor new Open VSX extension submissions without blocking them, allowing it to tune detections and reduce false positives ahead of enforcement.
Eclipse Foundation announces pre-publication checks for Open VSX
The Eclipse Foundation said it will add pre-publication security checks for Open VSX Registry extensions to detect issues such as namespace impersonation, exposed secrets, and known malicious patterns before publication. The move shifts Open VSX from a reactive takedown model to a proactive screening model aimed at reducing supply-chain risk.
Orca discloses GitHub Codespaces RCE attack vectors
On its Feb. 4 blog, Orca reported multiple ways malicious repositories or pull requests could abuse VS Code and devcontainer configuration in GitHub Codespaces to achieve remote code execution, exfiltrate tokens and secrets, and access hidden APIs.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


