BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Install Me Maybe: Turning Claimable VS Code Extensio
 n IDs into\n   Supply-Chain Attacks\n   Tags: DEF CON Official Talk | Expl
 oit 🪲\n   When: Saturday\, Aug 8\, 16:00 - 16:59 PDT\n   Where: LVCCW L
 evel 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1]Map\n\n   Description:\n\
 n   Developer tools trust extension identifiers way more than they should.
 \n\n   A VS Code extension ID like publisher.extension shows up everywhere
  a\n   dev environment gets set up\, and people treat it as the same trust
 ed\n   thing no matter where it's resolved\, but it isn't. Extension ident
 ity\n   is marketplace-specific. An extension can be trusted and popular i
 n\n   one marketplace while the matching namespace sits unclaimed in anoth
 er\n   that the main forks actually pull from. Claim that namespace\, publ
 ish\n   under the same identifier\, and a name people already trust now ru
 ns\n   your code. It's dependency confusion\, but for editor extensions. I
 've\n   been calling it Extension Confusion.\n\n   I'll show where the tru
 st boundary breaks\, the IDE quirks that carry\n   these identifiers acros
 s the gap\, and what happened when I published\n   proof-of-concept extens
 ions to measure it for real.\n\n   The scale got out of hand fast: 1M+ cal
 lbacks\, hundreds of\n   organizations\, $200k+ in bounties\, all in under
  3 months. Code running\n   on laptops\, managed corporate machines\, remo
 te dev setups\, WSL\, and\n   containers\, across SaaS\, fintech\, Fortune
  500s\, healthcare\,\n   government\, and universities.\n\n   A trusted na
 me\, a missing namespace\, and the marketplace gap no one\n   was watching
 .\n\n   Editor extensions are supply chain. Treat them that way.\n\n   My 
 talk from last year around malicious extensions can be a good\n   intro:\n
 \n     * https://www.youtube.com/watch?v=wI8ml8WqmQc\n\n   SpeakerBio:  Ra
 phael "rcss" Silva\n\n   Raphael Silva is a security researcher at Aikido 
 Security\, focused on\n   web security\, software supply-chain security\, 
 and vulnerability\n   research. He has spoken at DEF CON\, RootedCON\, OWA
 SP Global AppSec\,\n   Black Alps and OWASP local chapters\, and has also 
 run hands-on\n   activities at DEF CON. His work centers on finding weird 
 trust\n   assumptions in real systems\, turning them into clear attack mod
 els\,\n   and responsibly disclosing the results to vendors and open-sourc
 e\n   projects.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T235900Z
DTSTART:20260808T230000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Install Me Maybe: Turning Claimable VS Code Extension IDs into Supp
 ly-Chain Attacks
END:VEVENT
END:VCALENDAR
