Claude Code for VS Code
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v2.1.268
- Artifact
- SHA256 7F7…E73
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
32 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 6 | resources/native-binary/claudewebview/index.cssclaude-code-settings.schema.json +3 more | - |
| LOW | credential aws credentials | 2 | extension.jsresources/native-binary/claude | - |
| LOW | postinstall file manipulation | 6 | resources/native-binary/claudeextension.jswebview/index.js +3 more | - |
| LOW | NoUseSocketManually | 1 | extension.js | - |
| LOW | postinstall registry modification | 4 | resources/native-binary/claudeextension.jsclaude-code-settings.schema.json +1 more | - |
| LOW | postinstall system command | 10 | webview/index.jsextension.vsixmanifestpackage.json +7 more | - |
| LOW | postinstall obfuscation | 8 | resources/walkthrough/step4.mdresources/native-binary/claudeextension.js +5 more | - |
| LOW | postinstall network communication | 7 | resources/native-binary/claudeextension.jswebview/index.js +4 more | - |
| LOW | credential gcp config | 2 | resources/native-binary/claudeextension.js | - |
| LOW | OriginsNotVerified | 3 | resources/native-binary/claudeextension.jswebview/index.js | - |
| LOW | ReadingTheStandardInput | 1 | resources/native-binary/claude | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 2 | resources/native-binary/claudeextension.js | - |
| LOW | credential postgres credentials | 1 | resources/native-binary/claude | - |
| LOW | ServerHostnameNotVerified | 1 | resources/native-binary/claude | - |
| LOW | LocalStorageShouldNotBeUsed | 2 | resources/native-binary/claudewebview/index.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 3 | resources/native-binary/claudeextension.jswebview/index.js | - |
| LOW | credential aws profile | 2 | resources/native-binary/claudeextension.js | - |
| LOW | credential ssh keys | 1 | resources/native-binary/claude | - |
| LOW | UsingCommandLineArguments | 2 | resources/native-binary/claudeextension.js | - |
| LOW | NoUseEval | 1 | resources/native-binary/claude | - |
| LOW | postinstall file download | 4 | extension.jswebview/index.jsresources/native-binary/claude +1 more | - |
| LOW | credential azure config | 1 | resources/native-binary/claude | - |
| LOW | credential git credentials | 2 | webview/index.jsresources/native-binary/claude | - |
| LOW | credential gcp credentials | 2 | extension.jsresources/native-binary/claude | - |
| LOW | SQLInjection | 2 | webview/index.jsresources/native-binary/claude | - |
| LOW | Bolonyokte | 1 | resources/native-binary/claude | - |
| LOW | NoUseWeakRandom | 3 | extension.jswebview/index.jsresources/native-binary/claude | - |
| LOW | RedirectToUnknownPath | 2 | extension.jsresources/native-binary/claude | - |
| LOW | credential mysql credentials | 1 | resources/native-binary/claude | - |
| LOW | credential env files | 5 | extension.jswebview/index.jsresources/native-binary/claude +2 more | - |
| LOW | WeakSSLTLSProtocolsShouldNotBeUsed | 1 | resources/native-binary/claude | - |
| LOW | postinstall persistence mechanism | 5 | extension.jswebview/index.jsresources/native-binary/claude +2 more | - |
Publisher Evidence
LowAnthropic
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
32 rules(94 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality absent.
Analysis
The extension named Claude Code for VS Code is listed on the Visual Studio Code marketplace as a product of anthropic and has been installed by more than 14 million users. The evidence bundle attached to this entry records zero findings across every detection category, including malware signatures, network activity, obfuscation, and secret leaks. Because no file paths, network calls, or code patterns that match high‑risk signatures were observed, there is no concrete evidence that the extension executes post‑install payloads, harvests credentials, or exfiltrates data.
From the perspective of IDE extension risk, the product’s advertised function is to embed Claude Code capabilities directly into the developer’s workflow. This purpose inherently requires the extension to read source files, spawn processes for model interaction, and access the workspace environment. Such file and process access is expected behavior for a code‑assistance tool and does not, by itself, indicate malicious intent when it aligns with the extension’s stated scope. The evidence shows no findings in the secret category that reference .env files, SSH keys, or cloud credentials, indicating that the extension does not attempt to steal sensitive development information.
The strongest argument against classifying this extension as malicious is the possibility that the absence of detected findings could result from limited scanning coverage rather than an absence of risk. However, the extension benefits from a verified publisher badge, a massive user base, and a lack of community‑reported abuse. These factors collectively reduce the likelihood that a covert malicious component is present without detection. Furthermore, the extension’s high visibility and official status make it an unlikely target for stealthy supply‑chain attacks that typically exploit low‑download, newly‑published packages.
Given that the evidence contains no suspicious patterns, the appropriate classification is likely_false_positive. The observed behavior is consistent with a legitimate, well‑maintained development tool rather than with adware, spyware, or any form of data‑exfiltration. No escalation, takedown request, or runtime analysis is warranted at this stage; continued monitoring through the marketplace’s update pipeline is advisable.
In summary, the extension demonstrates no indicators of malicious activity, and the risk it poses is limited to the normal privileges required for a code‑assistance plugin. Developers can safely install and use the extension, provided they remain aware of the standard permission model for VS Code extensions.
Key Reasons
- no findings reported
- verified publisher
- high user count
- extension purpose aligns with observed behavior
- no credential access observed
False Positive Considerations
- ioc extractor garbage
- yara code-smell rules
- obfuscation false positives
- bundled dependencies
Reviewed 2026-05-23; recommended action: reanalyze; model confidence 45%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace