List of software quality issues with the number of affected components.
category ALL
Policies
Info
Category
Problem
Development extensions are commonly used by software developers to extend the functionality of integrated development environments, code editors, and other developer tools. Extensions are typically distributed through public marketplaces as packages that bundle the extension code with supporting resources. Development extension code implements behaviors that integrate it with the host application. This integration allows extensions to register commands, react to editor events, or provide programming language support. Extension code is loaded and executed automatically by the host application during events such as editor startup, file opening, or user interaction. These events are used by extension developers to set up the environment for nominal extension use, or to respond to activity within the host application. However, extensions are commonly abused by threat actors to execute arbitrary commands within the development environment. It was detected that the extension code could execute commands that are not typically used by development tools. Such unusual commands resemble common threat actor tactics and are usually obscured by layers of cryptography, code obfuscation, anti-analysis features, and other detection evasion techniques.
Prevalence in Visual Studio Code community
No prevalence information at this time
Next steps
Investigate reported detections.
Consult Mitre ATT&CK documentation: T1176.002 - Software Extensions: IDE Extensions.
If the development extension intent does not relate to the reported behavior, investigate your development environment for software supply chain compromise.
You should stop using the development extension until the investigation is completed, or until the issue is risk accepted.
Consider replacing the development extension with an alternative.
Problem
Development extensions are commonly used by software developers to extend the functionality of integrated development environments, code editors, and other developer tools. Extensions are typically distributed through public marketplaces as packages that bundle the extension code with supporting resources. Development extension code implements behaviors that integrate it with the host application. This integration allows extensions to register commands, react to editor events, or provide programming language support. Extension code is loaded and executed automatically by the host application during events such as editor startup, file opening, or user interaction. These events are used by extension developers to set up the environment for nominal extension use, or to respond to activity within the host application. It is unusual for certain types of development extensions to invoke commands that download additional content from a remote server. Attackers commonly abuse development extensions to fetch malicious payloads from public code repositories, file sharing websites, or their own infrastructure. Remotely hosted content is not immutable, allowing the attackers to change the type of malware they deploy at any time.
Prevalence in Visual Studio Code community
No prevalence information at this time
Next steps
Investigate reported detections.
Consult Mitre ATT&CK documentation: T1176.002 - Software Extensions: IDE Extensions.
If the development extension intent does not relate to the reported behavior, investigate your development environment for software supply chain compromise.
You should stop using the development extension until the investigation is completed, or until the issue is risk accepted.
Consider replacing the development extension with an alternative.
Problem
Development extensions are commonly used by software developers to extend the functionality of integrated development environments, code editors, and other developer tools. Extensions are typically distributed through public marketplaces as packages that bundle the extension code with supporting resources. Development extension code implements behaviors that integrate it with the host application. This integration allows extensions to register commands, react to editor events, or provide programming language support. Extension code is loaded and executed automatically by the host application during events such as editor startup, file opening, or user interaction. These events are used by extension developers to set up the environment for nominal extension use, or to respond to activity within the host application. It is unusual for certain types of development extensions to execute commands that can collect sensitive system information. Attackers often abuse development extensions to run commands that collect identifiable system information such as hostnames, user names, folder structures, and other data points that could help them understand the environment in which their malicious code was loaded.
Prevalence in Visual Studio Code community
No prevalence information at this time
Next steps
Investigate reported detections.
Consult Mitre ATT&CK documentation: T1176.002 - Software Extensions: IDE Extensions.
If the development extension intent does not relate to the reported behavior, investigate your development environment for software supply chain compromise.
You should stop using the development extension until the investigation is completed, or until the issue is risk accepted.
Consider replacing the development extension with an alternative.
Problem
Software components are typically distributed in standardized packaging formats. Software packages are built from instructions written within package manifests that act as blueprints for package assembly. A package manifest declares the most important software properties, such as the package name, its authors and license, external dependencies, and various actions that may occur during the package lifecycle. Package managers are specialized tools used by developers to manage software components. Package managers read these manifests to deploy software components along with their dependencies. The premise of the package management system is that software components are isolated from each other, and that they rely on the package manager to provide their dependencies. However, it was detected that a software component includes code capable of accessing or modifying directories that are maintained exclusively by package managers. This is unusual as it resembles tactics used by threat actors that tamper with installed software components and inject malicious code into trusted execution paths.
Prevalence in Visual Studio Code community
No prevalence information at this time
Next steps
Investigate reported detections as indicators of software tampering.
Consider rewriting the flagged code without using the marked behaviors.
Problem
Uniform Resource Locators (URLs) are structured addresses that point to locations and assets on the internet. URLs allow software developers to build complex applications that exchange data with servers that can be hosted in multiple geographical regions. URLs can commonly be found embedded in documentation, configuration files, source code and compiled binaries. One or more embedded URLs were discovered to link to raw files hosted on GitHub. Attackers often abuse popular web services to host malicious payloads. Since code-sharing service URLs are typically allowed by security solutions, using them for payload delivery increases the odds that the malicious code will reach the user. While the presence of code-sharing service locations does not imply malicious intent, all of their uses in a software package should be documented and approved. An increasing number of software supply chain attacks in the open source space leverage the GitHub service to deliver malicious payloads.
Prevalence in Visual Studio Code community
79 packages
found in
Top 100
622 packages
found in
Top 1k
4233 packages
found in
Top 10k
29.36k packages
in community
Next steps
Investigate reported detections.
If the software should not include these network references, investigate your build and release environment for software supply chain compromise.
You should delay the software release until the investigation is completed, or until the issue is risk accepted.
Consider an alternative delivery mechanism for software packages.
Problem
Software developers use programming and design knowledge to build reusable software components. Software components are the basic building blocks for modern applications. Software consumed by an enterprise consists of hundreds, and sometimes even thousands of open source components. Each of these components can have dozens or even hundreds of its own dependencies. When building applications, software developers download and install components from public repositories. For components to work properly, all of their dependencies also need to be installed. Some package repositories, like Node Package Manager (NPM), allow components to declare dependencies that are hosted remotely. Such dependencies are automatically downloaded from a specified location during software component installation. It was detected that a software component declares remote dependencies hosted outside commonly expected locations such as well-known code hosting platforms and official package registry content delivery networks. Threat actors often host malicious dependencies on attacker-controlled infrastructure, ephemeral file sharing services, or compromised legitimate sites to evade security review and retain control over the delivered content. It is uncommon to find open source components that resolve dependencies from such locations.
Consult Mitre ATT&CK documentation: T1195.001 - Supply Chain Compromise: Compromise Software Dependencies and Development Tools.
If the software component resolves dependencies from unusual locations, investigate the build and release environment for software supply chain compromise.
Consider vendoring the software component with all of its dependencies.
Avoid using this software package until it is vetted as safe.
Problem
Software components contain executable code that performs actions implemented during its development. These actions are called behaviors. In the analysis report, behaviors are presented as human-readable descriptions that best match the underlying code intent. While most behaviors are benign, some are commonly abused by malicious software with the intent to cause harm. When a software package shares behavior traits with malicious software, it may become flagged by security solutions. Any detection from security solutions can cause friction for the end-users during software deployment. While the behavior is likely intended by the developer, there is a small chance this detection is true positive, and an early indication of a software supply chain attack.
Prevalence in Visual Studio Code community
60 packages
found in
Top 100
434 packages
found in
Top 1k
2301 packages
found in
Top 10k
13.88k packages
in community
Next steps
Investigate reported detections.
If the software intent does not relate to the reported behavior, investigate your build and release environment for software supply chain compromise.
You should delay the software release until the investigation is completed, or until the issue is risk accepted.
Consider rewriting the flagged code without using the marked behaviors.
Problem
Uniform Resource Locators (URLs) are structured addresses that point to locations and assets on the internet. URLs allow software developers to build complex applications that exchange data with servers that can be hosted in multiple geographical regions. URLs can commonly be found embedded in documentation, configuration files, source code and compiled binaries. URL paths provide additional information to a web service when making a request. They are an optional, but an important part of the URL, as they may define specific content or actions based on the data being passed. Some parameters they pass might be considered sensitive information. Since path components are not encrypted this might cause sensitive information to leak. This issue is raised for URL paths than might contain information that attackers can easily intercept. Examples of sensitive information fields include passwords and other similar parameters.
Prevalence in Visual Studio Code community
39 packages
found in
Top 100
249 packages
found in
Top 1k
1056 packages
found in
Top 10k
5.32k packages
in community
Next steps
Investigate reported detections.
If the software should not include these network references, investigate your build and release environment for software supply chain compromise.
You should delay the software release until the investigation is completed, or until the issue is risk accepted.
Consider removing all references to flagged network locations.
Problem
Software composition analysis has identified a component with one or more known vulnerabilities. Based on the CVSS scoring, these vulnerabilities have been marked as low severity.
Prevalence in Visual Studio Code community
52 packages
found in
Top 100
388 packages
found in
Top 1k
2065 packages
found in
Top 10k
10.51k packages
in community
Next steps
Perform impact analysis for the reported CVEs.
Update the component to the latest version.
Lower severity vulnerabilities can be resolved with less urgency, but you should still make a plan to do so.
Problem
Uniform Resource Locators (URLs) are structured addresses that point to locations and assets on the internet. URLs allow software developers to build complex applications that exchange data with servers that can be hosted in multiple geographical regions. URLs can commonly be found embedded in documentation, configuration files, source code and compiled binaries. A port number is associated with a network address of a host, such as an IP address, and the type of network protocol used for communication. Within URLs, the ports are optional. Ports can be specified in a URL immediately following the domain name. Each network protocol, or schema, has a set of standard ports on which the service operates. This issue is raised when a mismatch between a network protocol and its expected port number is detected. While the presence of non-standard ports does not imply malicious intent, all of their uses in a software package should be documented and approved.
Prevalence in Visual Studio Code community
79 packages
found in
Top 100
560 packages
found in
Top 1k
2912 packages
found in
Top 10k
17.75k packages
in community
Next steps
Investigate reported detections.
If the software should not include these network references, investigate your build and release environment for software supply chain compromise.
You should delay the software release until the investigation is completed, or until the issue is risk accepted.
Consider changing the port to one that is standard for the networking protocol.