Product
VS Code
- First Reported
- May 14, 2026
- Latest Reported
- Oct 2, 2026
Reported Context (6)
- The Socket Threat Research team identified two suspicious VS Code themes still available on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme. Both present Socket traces a VS Code theme cluster across marketplaces to GlassWorm-linked malware
- "runOn": "folderOpen" in .vscode/tasks.json, triggering code when a developer opens the repository in a VS Code–compatible IDE. PolinRider Campaign Spreads Through Compromised GitHub Accounts and Packagist
- Microsoft products also fall into this group, including Windows 10 at 15.0%, Windows 11 at 13.9% and VS Code at 13.1%. These products may benefit from review, but they do not need the same level of testing on every Acronis Finds Patch Warning Rates Vary Widely Across SMB Windows Software
- that are routinely executed by developer tooling. Its targets include the @vscode/deviceid module inside VS Code, Cursor, and Antigravity; Discord Desktop’s core module; GitHub Desktop’s resources/app/main.js; and the Compromised Joyfill npm Beta Releases Deliver DEV#POPPER RAT
- VS Code / VS Code Insiders — settings.json, .mcp.json, mcpServers Compromised Jscrambler npm Releases Deliver Cross-Platform Infostealer
CVE (2)
Malware (4)
Threat Actors (1)
MITRE ATT&CK (40)
Vendors (9)
Products (87)
Tools (2)
Industries (3)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.