VSMEx

A Collection Tool and a Dataset of Malicious VS Code Extensions: Data/Toolset Paper

Conference Paper (2026)
Author(s)

Kotaiba Alachkar (TU Delft - Technology, Policy and Management)

Dirk Gaastra (Independent researcher)

Olga Gadyatskaya (Universiteit Leiden)

Eduardo Barbaro (TU Delft - Technology, Policy and Management)

Michel Van Eeten (TU Delft - Technology, Policy and Management)

Yury Zhauniarovich (TU Delft - Technology, Policy and Management)

Research Group
Organisation & Governance
DOI related publication
https://doi.org/10.1145/3800506.3803487 Final published version
More Info
expand_more
Publication Year
2026
Language
English
Research Group
Organisation & Governance
Pages (from-to)
138-144
Publisher
ACM
ISBN (electronic)
9798400725623
Event
16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026 (2026-06-23 - 2026-06-25), Frankfurt am Main, Germany
Downloads counter
50
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Visual Studio Code (VS Code) is one of the most widely used code editors, and its extension ecosystem has increasingly become a target for software supply chain attacks. Developing and validating effective detection techniques in this area requires ground-Truth data with both benign and malicious samples. While benign samples are easy to obtain, no publicly available or continuously updated dataset exists for malicious VS Code extensions. To address this gap, we built VSMEx, a continuously updated dataset of malicious VS Code extensions derived from Microsoft's official malicious and removed lists. Over a deployment period of more than three months, VSMEx successfully captured 214 extensions, demonstrating the viability of our approach. In this work, we present an initial analysis of the resulting dataset and share the associated metadata and the list of flagged or removed extensions collected during this period. In addition, we provide controlled access to the dataset itself, facilitating further research and contributing to the security of the VS Code ecosystem. Note that VSMEx continues to operate, making the resulting dataset well suited for training and validation in continuous machine learning settings.