Bloom Security’s Extension Resurrection research exposes a blind spot in developer security

https://media.thenextweb.com/2026/07/bloom-security-20m-seed-ai-enterprise-endpoint.jpg

TL;DR

Bloom Security’s “Extension Resurrection” research found that legitimate VS Code and Open VSX extension packs can reference extensions that don’t exist on the marketplace. Attackers could claim those namespaces and publish malicious extensions that install automatically through trusted packs. 677 of 4,179 VS Code packs and 94 of 321 Open VSX packs were vulnerable, with 500,000+ combined downloads. Both Microsoft and the Eclipse Foundation have since implemented protections after Bloom’s disclosure.

Security teams have spent years scrutinizing software dependencies, package repositories and build pipelines. Bloom Security‘s latest research suggests that another part of the software supply chain deserves closer attention: the extensions developers install inside their IDEs.

The company’s “Extension Resurrection” research examined extension packs on the Visual Studio Code Marketplace and Open VSX. Bloom found that legitimate packs could contain references to extensions that did not actually exist on the marketplace, creating an opportunity...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE