Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
extension-plugin-hijackbuild-pipeline-compromiseleaked-secret-api-keyai-platform-security

GitHub Codespaces and VS Code Extension Ecosystem Targeted in Developer Supply-Chain Attacks

Updated 3mo agoFirst seen Feb 7, 20262 sources

Security researchers reported multiple attack paths in GitHub Codespaces where opening a malicious repository or pull request can trigger remote code execution (RCE) by abusing repository-controlled VS Code configuration that Codespaces automatically honors (e.g., .vscode/ and .devcontainer/). The described impact includes arbitrary command execution inside the Codespace, exfiltration of GitHub tokens and secrets, and abuse of hidden APIs to access premium Copilot models—highlighting developer environments as a high-value supply-chain entry point because they often contain credentials outside centralized secret management.

In parallel, the Eclipse Foundation announced it will mandate pre-publish security checks for extensions uploaded to the Open VSX Registry to reduce supply-chain risk from malicious or compromised extensions. The planned controls aim to detect and quarantine suspicious uploads (e.g., namespace/name impersonation, accidentally published secrets, and known malicious patterns) before they are publicly available, following a trend of increased attacks on extension/package ecosystems (including recent cases where a compromised publisher account was used to ship poisoned updates).

Share:
GitHub Codespaces and VS Code Extension Ecosystem Targeted in Developer Supply-Chain Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 1, 20264mo ago

Open VSX plans enforcement of pre-publication checks

After the February monitoring phase, the Eclipse Foundation said enforcement of the new pre-publication security checks for Open VSX extensions would begin the following month.

Feb 4, 20265mo ago

Open VSX begins monitoring-only rollout of extension screening

The Eclipse Foundation said February 2026 would be used to monitor new Open VSX extension submissions without blocking them, allowing it to tune detections and reduce false positives ahead of enforcement.

Eclipse Foundation announces pre-publication checks for Open VSX

The Eclipse Foundation said it will add pre-publication security checks for Open VSX Registry extensions to detect issues such as namespace impersonation, exposed secrets, and known malicious patterns before publication. The move shifts Open VSX from a reactive takedown model to a proactive screening model aimed at reducing supply-chain risk.

Orca discloses GitHub Codespaces RCE attack vectors

On its Feb. 4 blog, Orca reported multiple ways malicious repositories or pull requests could abuse VS Code and devcontainer configuration in GitHub Codespaces to achieve remote code execution, exfiltrate tokens and secrets, and access hidden APIs.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Affected products
2 linked
Visual Studio CodeGithub Copilot
Organizations
7 linked
PathlockGitGuardianGitHubOrca SecuritySocketEclipse FoundationMicrosoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

GitHub Codespaces and VS Code Extension Ecosystem Targeted in Developer Supply-Chain Attacks | Mallory