Aikido researchers uncover malicious VS Code extensions capable of infecting thousands of developers. Mackenzie Jackson talks with Charlie Eriksen and Rami McCarthy about how the attack happened, why secrets matter, and what the new NPM security updates mean for developers.
Links:
Original Post from Aikido: / urn:li:activity:7384986044867256320
Wiz Security Research on VS Code https://www.wiz.io/blog/supply-chain-...
Rami McCarthy LinkedIn: / ramimac
Charlie Erkson Linkedin: / charlie-eriksen-a318578
⏱️ Chapters
00:00 — Introduction
00:31 — VS Code Extensions Turned Malicious
02:00 — Invisible Unicode Malware Explained
04:45 — Secrets and the Open VSX Ecosystem
07:25 — Why Secret Leaks Keep Happening
09:40 — How to Protect Developer Pipelines
11:00 — Open VSX vs Microsoft Marketplace
13:47 — NPM Security Updates
16:00 — Closing Thoughts
On this page of the site you can watch the video online Malicious VS Code Extensions: A Dive into the OpenVSX Malware Attack with a duration of hours minute second in good quality, which was uploaded by the user The Secure Disclosure | Cyber, Sake, More. 29 October 2025, share the link with friends and acquaintances, this video has already been watched 1,910 times on youtube and it was liked by 8 viewers. Enjoy your viewing!