Introducing Threat Center and Package Firewall for VS Code Extensions: Malware Protection From the Registry to the Developer Workstation
Blog post from Endor Labs
Amid increasingly frequent software supply-chain attacks involving compromised npm and PyPI packages, malicious AI-agent hooks, and poisoned VS Code extensions, the company is expanding its malware defenses across the development environment. Its new Threat Center provides real-time visibility into malicious packages in registries such as npm and PyPI, maps affected dependencies to customer projects, supplies malware details and research context, and issues alerts for emerging threats. Package Firewall, which already blocks malicious packages across several ecosystems, now scans and can prevent harmful VS Code extensions and updates from appearing in developers’ editor marketplaces. Deployed through existing mobile device management systems without persistent agents or workflow disruptions, the combined tools aim to identify new threats, assess application exposure through software composition analysis, and stop malicious components before they reach developer workstations or builds.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 2 | 649 | 155 | 80 | -85% |
| AI Coding Assistant | 1 | 341 | 115 | 55 | -77% |
| Secrets Management | 1 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.