Mazin Ahmed
mazen160.bsky.social
Mazin Ahmed
@mazen160.bsky.social
🚨 Disclosing a series of security bypasses in the Microsoft VS Code Marketplace that Microsoft doesn’t plan to fix anytime soon.

I presented the vectors at Black Hat MEA 2025 and just published the full breakdown.

🔗 Full post: mazinahmed.net/blog/publish...
Compromising Developers with Malicious Extensions - VS Code, Cursor AI, and the Backdoor You Didn't See Coming
Compromising Developers with Malicious Extensions - VS Code, Cursor AI, and the Backdoor You Didn't See Coming.
mazinahmed.net
December 6, 2025 at 10:36 AM