vscode
Safeguard articles tagged "vscode" — guides, analysis, and best practices for software supply chain and application security.
5 articles
Eighteen Minutes: The Nx Console Extension Compromise and the IDE Blind Spot
A poisoned VS Code extension was live for eighteen minutes. In that window, auto-update pushed it into every developer environment with Nx Console installed — including a GitHub employee's device, leading to exfiltration of internal GitHub repositories. Your IDE extensions have no SBOM, no review, and a direct push channel to your engineers.
VS Code marketplace incident postmortem: what 2023-2024 actually taught us
Between 2023 and 2024 the VS Code Marketplace saw a string of typosquat, hijack, and impersonation incidents that shaped Microsoft's eventual hardening response. This is a composite postmortem of what happened, what changed, and what is still broken in 2026.
Safeguard IDE Extension v5: Security Feedback Where Developers Actually Work
The Safeguard IDE Extension v5 brings SBOM generation, vulnerability alerts, and policy checks directly into VS Code and JetBrains IDEs. A deep dive into what changed and why it matters.
VS Code Marketplace Malware Campaigns in 2025
A senior engineer's review of the 2025 VS Code Marketplace malware wave, including typosquats, trojanized themes, and extensions that stole npm tokens at scale.
VS Code Extensions and Supply Chain Risk in 2026
VS Code extensions run with full editor privileges and broad filesystem access. A look at the real attacks, the marketplace's blind spots, and how to harden the workstation.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.