Plugins Gone Rogue: Attacking Developer Environments @OWASPGLOBAL
Plugins Gone Rogue: Attacking Developer Environments  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
When attackers compromise a developer’s IDE, they own the code before it even reaches production.

VSCode and Visual Studio plugins have minimal security oversight, making them a prime target for attacker-controlled backdoors. In this talk, I’ll cover original research into compromising IDE components and plugins. Attendees will:

- Learn how plugin ecosystems work and why they’re so easy to exploit
- See demonstrations of practical PoCs of backdoored plugins for VSCode and Visual Studio that steal credentials, inject malicious code, and more
- Understand how attackers leverage plugin marketplace manipulation: how they use fake reviews, typosquatting, and dependency hijacking to push malicious plugins

Expect a technical deep dive into real-world exploitation techniques, showcasing how attackers are leveraging overlooked security gaps in developer tooling.

Raphael Silva
Checkmarx
Security Researcher

Raphael Silva is a Security Researcher at Checkmarx, specializing in security research, SAST methodologies, and Supply Chain Security. Over the course of his career, he has presented at various conferences (RootedCon, OWASP Global AppSec, OWASP Local Chapters), as well as conducted a workshop at DEFCON. In addition, he is experienced in vulnerability analysis, research, and disclosure, having reported multiple bugs to companies and open-source projects.
@0x_rcss
linkedin.com/in/raphaelcssilva
checkmarx.com (company)

Managed by the OWASP® Foundation
owasp.org
Plugins Gone Rogue: Attacking Developer Environments202008 August 2020 Global Board MeetingFrom Logs to Defense: Building AI Enhanced XDR Pipelines for Application Level Threats track 1OWASP Global Board of Directors Meeting - July 2025OWASP Top 10 AnnoucementLessons Learned: AppSec Role Based Training 5 Years Ups, Downs, FuturesAutomated Security Testing with OWASP NettackerOWASP Finance SummaryOWASP Board of Directors - January 2026OWASP DefectDojo - Matt TesauroFrom Soft Skills to Hard Data: Measuring the Impact of Culture and Security ChampionsBusinesses Run On Risk And Debt: Why Communicating Security Risk Is Hard - Dwayne McDaniel
OWASP Foundation |

Plugins Gone Rogue: Attacking Developer Environments

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER