vsix scanner

vsix scanner


This taught us a lot:

  1. The problem is much larger than just VSCode. First of all, Visual Studio shares the same Marketplace but its extensions are very different
  2. When creating AI-powered tooling, there needs to be a strict boundary between traditional, deterministic scanning and when AI takes the wheel.
  3. As Red Teamers, creating a security product is a disaster as every feature we implement causes us to spend hours thinking about how to bypass it.

This is how it works:

  1. First, set up extension whitelisting on all developer computers
  2. If an engineer needs to install a new extension that’s not allowed, they message the extension ID to a Teams agent
  3. The agent passes the extension ID to an isolated container, unpacks it and then runs several scans for malware. At this point, it’s important to use our tried and tested, reproducible tools instead of relying on AI here
  4. The agent reads the results of the malware scans using a very detailed system prompt to reach a verdict. This verdict as well as some detail is sent to a security analyst.
  5. The security analyst will receive all of the right information and click either “Approve” or “Deny”
  6. Approved extensions get pushed to a whitelist, and then trigger Intune to deploy the updated whitelist to hosts
  7. Denied requests get flagged

It’s important to give engineers a low-friction way of getting the tools that they need, otherwise they’ll work around security controls. That’s why we chose to build in smooth Teams integration (although the agent could be hooked up to any messaging service). Simply send the extension ID, contact the analyst if they’re taking too long, and the whole process takes minutes, not days.

At the moment, VSCody isn’t public. We’re still finding nuances that previous versions didn’t cover and improving it.

What This Means for Your Organisation

Engineers are high-value targets as their machines touch source code, cloud credentials, and production systems. It’s not easy, but we think it’s worth sitting down with your security team and understanding how they view developer tooling:

  • Some developers use Visual Studio instead, which has its own extension marketplace and does NOT support whitelisting liked VSCode does
  • They might use another IDE entirely, like Eclipse, Jetbrains, or Cursor
  • You’ll need to collect a full list of extensions currently used by developers so they can be loaded into the whitelist from day 1