VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

In recent weeks, supply chain attacks have become a growing concern, with multiple major repositories suffering from fake updates pushed by malicious actors to spread malware. In particular, recent incidents involving malicious VS Code extensions have demonstrated how threat actors can abuse trusted software distribution channels to gain access to source code, credentials, cloud resources, and other sensitive assets. To help fight back against this threat, Microsoft has introduced a new security-focused change to Visual Studio Code that delays automatic updates for most extensions by two hours after a new version is published. Beginning with VS Code version 1.123, the delay is intended to provide a brief review and response window before updates are automatically distributed to users. During this period, potentially malicious or compromised extensions can be identified and removed before they reach a large number of developer systems. Users can still choose to install updates manually at any time, while the editor will display information about pending updates and the scheduled installation time.


This move aligns VS Code with a broader trend across software package ecosystems. Several package managers and repositories have recently implemented publication cooldown periods, minimum package age requirements, or delayed deployment mechanisms designed to prevent newly published malicious packages from spreading immediately. Security agencies and researchers have increasingly warned organizations that supply chain attacks are becoming more common, particularly in ecosystems that rely heavily on third-party dependencies and automated update mechanisms. The objective is not to eliminate supply chain attacks entirely, but to reduce the “blast radius” of a compromised release by creating a narrow but valuable opportunity for detection and intervention before widespread adoption occurs.


Microsoft noted that the new delay does not apply to extensions published by certain trusted organizations, including Microsoft, GitHub, and OpenAI, whose updates will continue to deploy immediately. While the measure does not eliminate the risk of extension-based attacks, it creates an additional layer of protection by giving marketplace operators and security teams more time to detect and revoke malicious releases before they are widely installed. While the security community generally views the change as a positive step, many practitioners have argued that a two-hour delay may be too short to significantly disrupt sophisticated supply chain attacks. Community discussions have suggested that longer configurable delays, staged rollouts, extension allowlists, stronger publisher verification, and more granular permission controls may ultimately provide greater protection. Nevertheless, Microsoft’s decision reflects an important shift in thinking: rather than assuming every published update is trustworthy, platform operators are increasingly introducing friction into the update process to give defenders time to identify malicious activity before it propagates throughout the software ecosystem.

Share

Related Posts

bw-blog_un-1764705703306-e20b4b482ce1
kevin-shi-f2krpIYBrJc-unsplash
tsd-studio-r5hWJI-LmgA-unsplash

Copyright © All Right Reserved

Privacy Policy