Editor pluginVS Code

An extension can run a task the moment you open a folder.

A VS Code extension runs with your editor's privileges. Extuno diffs each update, then runs the new version to see what it does with that privilege. Static, dynamic, and AI analysis on every scan. A task that fires on folder open is caught before you open the folder.

In shortTo check a VS Code plugin for supply-chain risk, scan the published artifact, not just the source, and compare each new version against the last. Extuno runs static analysis, a dynamic sandbox, and AI review across every VS Code release, then reports evidence on every finding.
VS Code - live inspectionexample
acme.theme-pro 4.2.0
vs code plugin
4.1.0->4.2.0
Static
Dynamic
AI
Analyzing update
What Extuno catches in VS Code

Every finding is backed by evidence.

Each finding names the change, why it is dangerous, and the recommended action.

Diff finding

Workspace-trust abuse

An update auto-runs a task on folder open, before you opt in.

Critical
Diff finding

Credential theft

The extension reads ~/.aws and environment tokens and exfiltrates them.

Critical
Diff finding

New child process

A build step spawns a shell that was not present in the prior version.

Review
See it on a poisoned update

From editor trust to token theft

Extuno runs the extension in a sandbox and records the exact chain from trust prompt to exfiltration.

  • + Vulnerability and secret-leak testing on every version
  • + Static analysis reads the code without running it
  • + Dynamic sandbox runs it live and records behavior
  • + AI code analysis reads the full source and correlates the change against prior versions
How it works
  1. 1Open workspace
  2. 2Extension requests trust
  3. 3Runs a build task
  4. 4Spawns hidden shell
  5. 5Exfiltrates ~/.aws + tokens

Scan your first VS Code plugin free.

5 free credits on signup. One credit per scan, no card required.

FAQ

Common questions

Does Extuno support VS Code?

Yes. Extuno scans VS Code with static analysis, a dynamic sandbox, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.

How does Extuno scan VS Code?

Extuno acquires the published VS Code artifact, reads it statically with 1100+ rules, runs it in a network-segmented sandbox, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.

What does Extuno catch in VS Code?

Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.