UntrustIDE: Exploiting Weaknesses in VS Code Extensions
Elizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck, Alexandros Kapravelos
摘要
—With the rise in threats against the software supply chain, developer integrated development environments (IDEs) present an attractive target for attackers. For example, researchers have found extensions for Visual Studio Code (VS Code) that start web servers and can be exploited via JavaScript executing in a web browser on the developer’s host. This paper seeks to systematically understand the landscape of vulnerabilities in VS Code’s extension marketplace. We identify a set of four sources of untrusted input and three code targets that can be used for code injection and file integrity attacks and use them to design taint analysis rules in CodeQL. We then perform an ecosystem-level analysis of the VS Code extension marketplace, studying 25,402 extensions that contain code. Our results show that while vulnerabilities are not pervasive, they exist and impact millions of users. Specifically, we find 21 extensions with verified proof of concept exploits of code injection attacks impacting a total of over 6 million installations. Through this study, we demonstrate the need for greater attention to the security of IDE extensions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the WildYi Liu, Zhihao Chen, Yanjun Zhang, Gelei Deng 等USENIX Security 2026 · 被引用 46 次
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines 等ICSE 2026 · 被引用 5 次
- From Noise to Signal: Precisely Identify Affected Packages of Known Vulnerabilities in npm EcosystemYingyuan Pu, Lingyun Ying, Yacong GuNDSS 2026 · 被引用 4 次
- Too Much of a Good Thing: (In-)Security of Mandatory Security Software for Financial Services in South KoreaTaisic Yun, Suhwan Jeong, Yonghwa Lee, Seungjoo Kim 等USENIX Security 2025
它引用的顶会 Paper4
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 被引用 91 次
- Containing Malicious Package Updates in npm with a Lightweight Permission SystemGabriel Ferreira, Limin Jia, Joshua Sunshine, Christian KästnerICSE 2021 · 被引用 3 次
- A Security Study about Electron Applications and a Programming Methodology to Tame DOM FunctionalitiesZihao Jin, Shuo Chen, Yang Chen, Haixin Duan 等NDSS 2023
相关 Paper
- Continuous Intrusion: Characterizing the Security of Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao 等S&P 2023
- ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsSiddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl 等USENIX Security 2023
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 被引用 88 次
- ReactAppScan: Mining React Application Vulnerabilities via Component GraphZhiyong Guo, Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo 等CCS 2024 · 被引用 3 次
- Toward Understanding the Security of Plugins in Continuous Integration ServicesXiaofan Li, Yacong Gu, Chu Qiao, Zhenkai Zhang 等CCS 2024
