Trendyol Tech
Read post

When Your IDE Becomes a RCE Endpoint

Trendyol's CSOC and Application Security team uncovered a live supply-chain attack technique targeting Cursor, Windsurf, VSCodium, and other VS Code forks that resolve extensions from OpenVSX. Because Microsoft's Marketplace and OpenVSX are separate trust roots with no shared ownership, attackers can register abandoned or unclaimed publisher.extension namespaces on OpenVSX and silently deliver malicious code to any developer using an affected editor. A full comparison of 129,000 Microsoft Marketplace extensions against 14,194 OpenVSX entries revealed 104,456 squat-ready namespaces, 1,078 publisher mismatches, and 126 exact-ID hijacks including high-install extensions like sumneko.lua and rust-lang.rust. The post walks through the full 8-step attack chain, explains how Cursor's June 2025 migration to OpenVSX dramatically expanded the blast radius, and provides CrowdStrike Falcon detection queries using CURSOR_SPAWN* environment variables. Recommended mitigations include enforcing an organization-wide extension allowlist, enabling auto-update cooldowns, auditing installed extensions against OpenVSX ownership, and treating developer endpoints as production-equivalent assets.

    #security
Jun 29•27m read time•From medium.com
Post cover image
Table of contents
How we found ourselves looking at thisMeasuring the blast radiusHow Cursor decides what to installWhat changed in June 2025Get Berk ALBAYRAK’s stories in your inboxWalking through an attack, step by step
9.9K Impressions1 Comment
Trendyol Tech's image
Trendyol Tech

Trendyol Tech Blog offers a glimpse into the technology and engineering practices powering one of Tu...

78 Followers

•

988 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard