Supply chain, DevOps

Access tokens exposed by numerous VSCode extensions pose supply chain risk

(Credit: MCGORIE – stock.adobe.com)

More than 100 VSCode extensions revealed personal access tokens, presenting a significant software supply chain threat to developers, The Hacker News reports.

Over 550 validated secrets, including those from artificial intelligence and cloud security providers, as well as databases, were also present in more than 500 extensions, an analysis from Wiz Research showed. Attackers could have exploited one of the leaked PATs to facilitate a malware intrusion against a major Chinese enterprise, according to researchers.

All of the exposed VSCode PATs have since been revoked by Microsoft, which has noted the imminent inclusion of clandestine scanning features for extensions.

"The issue highlights the continued risks of extensions and plugins, and supply chain security in general. It continues to validate the impression that any package repository carries a high risk of mass secrets leakage," said Wiz.

Such findings follow a Koi Security report detailing at least 11 nefarious VSCode extensions used by the threat actor TigerJack to facilitate cryptocurrency mining and arbitrary JavaScript execution for further systems compromise as part of a coordinated attack campaign.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds