VS Code Marketplace Verified

Claude Code for VS Code

by Anthropic · 26.3M users · 3.7 rating
f46f2b79-e8cd-5566-a849-d924999d8db5 | v2.1.282
65/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v2.1.268
Artifact
SHA256 7F7…E73
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

98 detail rows

YARA Rule Matches

32 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 6
resources/native-binary/claudewebview/index.cssclaude-code-settings.schema.json +3 more
-
LOWcredential aws credentials 2
extension.jsresources/native-binary/claude
-
LOWpostinstall file manipulation 6
resources/native-binary/claudeextension.jswebview/index.js +3 more
-
LOWNoUseSocketManually 1
extension.js
-
LOWpostinstall registry modification 4
resources/native-binary/claudeextension.jsclaude-code-settings.schema.json +1 more
-
LOWpostinstall system command 10
webview/index.jsextension.vsixmanifestpackage.json +7 more
-
LOWpostinstall obfuscation 8
resources/walkthrough/step4.mdresources/native-binary/claudeextension.js +5 more
-
LOWpostinstall network communication 7
resources/native-binary/claudeextension.jswebview/index.js +4 more
-
LOWcredential gcp config 2
resources/native-binary/claudeextension.js
-
LOWOriginsNotVerified 3
resources/native-binary/claudeextension.jswebview/index.js
-
LOWReadingTheStandardInput 1
resources/native-binary/claude
-
LOWUsingShellInterpreterWhenExecutingOSCommands 2
resources/native-binary/claudeextension.js
-
LOWcredential postgres credentials 1
resources/native-binary/claude
-
LOWServerHostnameNotVerified 1
resources/native-binary/claude
-
LOWLocalStorageShouldNotBeUsed 2
resources/native-binary/claudewebview/index.js
-
LOWDebuggerStatementsShouldNotBeUsed 3
resources/native-binary/claudeextension.jswebview/index.js
-
LOWcredential aws profile 2
resources/native-binary/claudeextension.js
-
LOWcredential ssh keys 1
resources/native-binary/claude
-
LOWUsingCommandLineArguments 2
resources/native-binary/claudeextension.js
-
LOWNoUseEval 1
resources/native-binary/claude
-
LOWpostinstall file download 4
extension.jswebview/index.jsresources/native-binary/claude +1 more
-
LOWcredential azure config 1
resources/native-binary/claude
-
LOWcredential git credentials 2
webview/index.jsresources/native-binary/claude
-
LOWcredential gcp credentials 2
extension.jsresources/native-binary/claude
-
LOWSQLInjection 2
webview/index.jsresources/native-binary/claude
-
LOWBolonyokte 1
resources/native-binary/claude
-
LOWNoUseWeakRandom 3
extension.jswebview/index.jsresources/native-binary/claude
-
LOWRedirectToUnknownPath 2
extension.jsresources/native-binary/claude
-
LOWcredential mysql credentials 1
resources/native-binary/claude
-
LOWcredential env files 5
extension.jswebview/index.jsresources/native-binary/claude +2 more
-
LOWWeakSSLTLSProtocolsShouldNotBeUsed 1
resources/native-binary/claude
-
LOWpostinstall persistence mechanism 5
extension.jswebview/index.jsresources/native-binary/claude +2 more
-

Publisher Evidence

Low

Anthropic

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
anthropic.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
5
Portfolio

11 evidence rows available.

Finding Categories

4
Obfuscation

YARA Rules Matched

32 rules(94 hits)
postinstall crypto operations credential aws credentials postinstall file manipulation NoUseSocketManually postinstall registry modification postinstall system command postinstall obfuscation postinstall network communication credential gcp config OriginsNotVerified ReadingTheStandardInput UsingShellInterpreterWhenExecutingOSCommands credential postgres credentials ServerHostnameNotVerified LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed +16 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality absent.

Analysis

The extension named Claude Code for VS Code is listed on the Visual Studio Code marketplace as a product of anthropic and has been installed by more than 14 million users. The evidence bundle attached to this entry records zero findings across every detection category, including malware signatures, network activity, obfuscation, and secret leaks. Because no file paths, network calls, or code patterns that match high‑risk signatures were observed, there is no concrete evidence that the extension executes post‑install payloads, harvests credentials, or exfiltrates data.

From the perspective of IDE extension risk, the product’s advertised function is to embed Claude Code capabilities directly into the developer’s workflow. This purpose inherently requires the extension to read source files, spawn processes for model interaction, and access the workspace environment. Such file and process access is expected behavior for a code‑assistance tool and does not, by itself, indicate malicious intent when it aligns with the extension’s stated scope. The evidence shows no findings in the secret category that reference .env files, SSH keys, or cloud credentials, indicating that the extension does not attempt to steal sensitive development information.

The strongest argument against classifying this extension as malicious is the possibility that the absence of detected findings could result from limited scanning coverage rather than an absence of risk. However, the extension benefits from a verified publisher badge, a massive user base, and a lack of community‑reported abuse. These factors collectively reduce the likelihood that a covert malicious component is present without detection. Furthermore, the extension’s high visibility and official status make it an unlikely target for stealthy supply‑chain attacks that typically exploit low‑download, newly‑published packages.

Given that the evidence contains no suspicious patterns, the appropriate classification is likely_false_positive. The observed behavior is consistent with a legitimate, well‑maintained development tool rather than with adware, spyware, or any form of data‑exfiltration. No escalation, takedown request, or runtime analysis is warranted at this stage; continued monitoring through the marketplace’s update pipeline is advisable.

In summary, the extension demonstrates no indicators of malicious activity, and the risk it poses is limited to the normal privileges required for a code‑assistance plugin. Developers can safely install and use the extension, provided they remain aware of the standard permission model for VS Code extensions.

Key Reasons

  • no findings reported
  • verified publisher
  • high user count
  • extension purpose aligns with observed behavior
  • no credential access observed

False Positive Considerations

  • ioc extractor garbage
  • yara code-smell rules
  • obfuscation false positives
  • bundled dependencies

Reviewed 2026-05-23; recommended action: reanalyze; model confidence 45%.

About This Extension

Claude Code for VS Code: Harness the power of Claude Code without leaving your IDE

Frequently Asked Questions