Sign in

tuckner

@johntuckner.me
807 followers 294 following 459 posts

Working on finding bad software extensions.

PostsRepliesMedia
tuckner @johntuckner.me · 20/05/2026
Excited to secure the developer endpoint right as everyone is becoming a developer
032
Reposted by tuckner
Feross @feross.bsky.social · 28/04/2026
. @socket.dev just acquired @secureannex.com, the extension security company built by @johntuckner.me. John is joining Socket. John built Secure Annex as a solo founder into a product that security teams at Reddit, Brave, Torq, and Movable Ink depend on.
2143
tuckner @johntuckner.me · 28/04/2026
Thank you! You were there at the very start! Hope you're doing well
000
tuckner @johntuckner.me · 28/04/2026
Today we're announcing that @secureannex.com has been acquired by @socket.dev! Supply chain security is a deceptively wide problem from open source code to browser extensions. Developers and IT teams can't stop it from impacting their organization alone. secureannex.com/blog/annex-a...
173
tuckner @johntuckner.me · 26/02/2026
We tracked this one from the moment it was listed for sale Oct 11th, through the ownership change, to the malicious update Feb 17th. Full technical breakdown of the pixel trick, the C2 infrastructure, and the CSP stripping. annex.security/blog/pixel-p...
annex.security
Pixel Perfect: Sold Extension Injects Code Through Pixel
A Google Lens extension that was sold gets weaponized overnight—stripping browser security headers and using a 1x1 GIF onload trick to execute C2-delivered JavaScript on every page
001
tuckner @johntuckner.me · 26/02/2026
The original extension still works perfectly. Google Lens integration, screen capture, all of it. Users would never notice anything beyond a single permission acceptance prompt. That's what makes extension supply chain attacks so dangerous.
100
tuckner @johntuckner.me · 26/02/2026
The new owner added a C2 server, stripped important security headers from all pages, and used a 1x1 invisible pixel's onload handler to execute remote JavaScript in pages. The actual malicious code never appears in the extension's source files, but the code update was worrying
100
tuckner @johntuckner.me · 26/02/2026
A Chrome extension with 7,000 users and a Google Featured badge was recently sold, weaponized, and pushed a malicious update to that executed code through a hidden pixel. Here's how it worked 👇
100
tuckner @johntuckner.me · 04/02/2026
LimaCharlie released their Agentic SecOps Workspace recently which runs Claude Code in their UI including MCP servers. It's never been so easy to just say 'look at my detections and research the extensions'. Even though 1Password falls under an unapproved policy, at least it isn't malicious!
000
tuckner @johntuckner.me · 31/01/2026
Extension analysis located here: app.secureannex.com/extensions/i...
app.secureannex.com
Annex
Browser extension protection and management.
000
tuckner @johntuckner.me · 31/01/2026
What a mess and this isn't the first time this has happened! oorzc.mind-map@1.0.61 oorzc.i18n-tools-plus@1.6.8 oorzc.ssh-tools@0.5.1 (removed) oorzc.scss-to-css-compile@1.3.4 It is these incremental compromises that will become a widespread incident.
100
tuckner @johntuckner.me · 31/01/2026
1. Your extension will auto update 2. The malicious versions will be removed from Open VSX so no trace 3. Your extension will not downgrade itself 4. Victims will have to wait until the real developer publishes a new version to update 5. If the extensions are removed, they won't uninstall
100
tuckner @johntuckner.me · 31/01/2026
As predicted - "oorzc" a developer with extensions totalling 25,000 legitimate installs across 4 extensions looks to have had their Open VSX account compromised and published malicious updates. The worst part is this...
110
tuckner @johntuckner.me · 28/01/2026
The next supply chain worm has been seeded in Open VSX. A cloned Angular extension with 5000 downloads has been available for two weeks and was updated with malware 6 days ago. This multi stage attack uses etherhiding, gcal c2, rust implants, and more. annex.security/blog/worms-l...
annex.security
Worms lurking in code extensions
Worms are hiding discreetly in extension marketplaces waiting to trigger the next mass scale event.
022
tuckner @johntuckner.me · 28/01/2026
Obsidian Security identifies a set of 25 extensions impersonating popular AI providers affecting over 500,000 real users by stealing API keys, prompt poaching, and capturing search queries. It's the wild west in the extension store! www.obsidiansecurity.com/blog/small-t...
obsidiansecurity.com
Small Tools, Big Risk: When Browser Extensions Start Stealing API Keys
001
tuckner @johntuckner.me · 19/01/2026
If you've had to listen to me over the last couple months, it's likely you would've hear me say that all of our most important apps will have extensions or plugins for integration. Think we're learning from past mistakes?
010
tuckner @johntuckner.me · 16/01/2026
A browser extension, PasteReady, was listed for sale last May became malicious after an ownership transfer on December 27th. Many organizations have been impacted by extensions which changed hands. @secureannex.com watches for transfers and warns you in advance! www.linkedin.com/pulse/paster...
linkedin.com
PasteReady: Danger of sold extensions
The PasteReady browser extension (dcbikjphkkgmgmjoohmbnhccbndgpmin) was sold and the new owner pushed malware immediately after taking ownership. PasteReady was put up for sale on http://extensionhub.
010
tuckner @johntuckner.me · 14/01/2026
Pyrefly - Python Language Tooling by Meta is the 4th most used extension in Open VSX. Be careful downloading the 'Pro' version in Cursor hoping you'll get some extra features, it is published by 'casendsabotnu954' who just joined GitHub the other day. Textbook cloning and staging behavior!
010
tuckner @johntuckner.me · 08/01/2026
Loving a new detection that identifies code extensions published by new and lightly used GitHub accounts.This time it instantly caught an extension impersonating JFrog which already has over 10k downloads.
021
tuckner @johntuckner.me · 05/01/2026
Not the "pulling a Rabbit out of a hat" magic trick that most want. This Firefox extension completely changes from a "Simple Label Editor" to a Rabby wallet stealer overnight.
011
tuckner @johntuckner.me · 29/12/2025
A browser extension with over a million users is poaching the prompts of leading AI chat tools. SimilarWeb loads obfuscated remote configuration to collect the prompts, responses and metadata of your conversations. Your private thoughts are analytics companies gain. secureannex.com/blog/prompt-...
secureannex.com
Prompt poaching runs rampant in extensions
Web analytics companies are using browser extensions to monetize your most private thoughts
000
tuckner @johntuckner.me · 17/12/2025
These code comments are an improvement from: 1. Request malware 2. Download malware 3. Make malware executable 4. Run malware This is the extent of the extension available in the VS Marketplace. Installs a Mythic agent from the C2.
030
tuckner @johntuckner.me · 10/12/2025
Monitoring a large influx of AI slop extensions that are reposting a marginally refactored but known malicious package. The marketplace listings are packed with emojis and a couple sections of 'features'. This one made the mistake of linking to an already known piece of malware.
020
tuckner @johntuckner.me · 09/12/2025
Welcome to Antigravity the newest most advanced agentic AI development tool by Google... ... uses Open VSX for extensions and shows malicious listings to users.
010
tuckner @johntuckner.me · 05/12/2025
Changing how an extension looks in a marketplace doesn't require new code to be pushed. Check out the magic when this "Test Extension" magically turns into a "solidity" extension after being published. Review the full lineage of a marketplace listing using the new date picker in Secure Annex.
020
tuckner @johntuckner.me · 05/12/2025
Vibed coded malicious extensions are getting out of hand! This 'theme' downloads a malicious zip, unpacks it, and runs it silently with PowerShell.
010
tuckner @johntuckner.me · 02/12/2025
16 Firefox extensions with the almost the same name, same permhash requesting the most sensitive permission combinations like <all_urls> and cookies. Something being staged?
010
tuckner @johntuckner.me · 01/12/2025
Glassworm returned in a big way during the holiday. We're tracking 23 code extensions across the VS Marketplace and Open VSX which copy popular extensions, evade filters, manipulate their download counts, and then update with sinister malware. secureannex.com/blog/glasswo...
secureannex.com
Glassworm stays prevalent
Glassworm attacks look to take full advantage of the holidays
022
tuckner @johntuckner.me · 01/12/2025
Resembles Glassworm signatures loading a rust binary. Some of the activation code is tucked into copied extensions, but still runs on activate.
000
tuckner @johntuckner.me · 01/12/2025
Malware in Open VSX and available in Cursor right now tailwind-nuxt.tailwindcss-for-react flutcode.flutter-extension yamlcode.yaml-vscode-extension
100
tuckner @johntuckner.me · 28/11/2025
vims-vsce.vscode-vim yamlcode.yaml-vscode-extension solblanco.svetle-vsce Open VSX: saoudrizvsce.claude-dev saoudrizvsce.claude-devsce vitalik.solidity 3/3
000
tuckner @johntuckner.me · 28/11/2025
prisma-inc.prisma-studio-assistance prettier-vsc.vsce-prettier flutcode.flutter-extension csvmech.csvrainbow codevsce.codelddb-vscode saoudrizvsce.claude-devsce clangdcode.clangd-vsce cweijamysq.sync-settings-vscode bphpburnsus.iconesvscode klustfix.kluster-code-verify 2/3
100
tuckner @johntuckner.me · 28/11/2025
Unprecedented code extension attacks this week. All are name squatting on popular tools. Only a couple have had malware deployed, many are still staging, few have been removed from marketplaces. There may be more coming. VS Marketplace: iconkieftwo.icon-theme-materiall 1/3
100
tuckner @johntuckner.me · 24/11/2025
Imagine how useful it would be if the Chrome Web Store showed you users over time. This ad blocker went from 0 to 40,000 users overnight! 🤔
010
tuckner @johntuckner.me · 20/11/2025
Going to have to reread Hacking: The Art of Exploitation, 2nd Edition by Jon Erickson in order to keep up with the advanced tactics we're starting to see in VS Code extension malware.
030
tuckner @johntuckner.me · 19/11/2025
Really excited to being supporting crxaminer.tech with some Secure Annex details. Looking forward to more opportunities to get more information on browser extensions out there!
010
tuckner @johntuckner.me · 18/11/2025
Mackenzie Jackson is raising a red flag about the risks IDE extensions present. Always on top of the top industry trends. Thanks for letting me share a bit! m.youtube.com/watch?v=FiJ_...
youtube.com
- YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
010
tuckner @johntuckner.me · 17/11/2025
The extension was approved, now what? Are you going back tomorrow to see if it changed? You know they auto update instantly right? Rolling out to Secure Annex - code change alerts. This compares past code with additional context to understand how an extension is changing over time. Catch bad quick!
020
tuckner @johntuckner.me · 14/11/2025
If you like this, you'll enjoy reading about 50 other hidden extensions found previously which are pushed to users via advertisements. arstechnica.com/security/202...
arstechnica.com
Researcher uncovers dozens of sketchy Chrome extensions with 4 million installs
Even weirder: Why would Google give so many the “Featured” stamp for trustworthiness?
010
tuckner @johntuckner.me · 14/11/2025
A brand new unlisted extension with 100,000 users? 41 ratings? Must be really valuable. Nope - completely manipulated stats and it doesn't even contain real code. It exists only to collect your searches and earn Bing Rewards.
144
tuckner @johntuckner.me · 12/11/2025
We've found code extensions openly call themselves malware in the VS Code marketplace recently and now browser extensions posing as known malicious remote access tools to the Chrome Web Store. What gives?
000
tuckner @johntuckner.me · 11/11/2025
Attracting a lot of fans these days
010
tuckner @johntuckner.me · 11/11/2025
Did you know you can manage an allowlist of MCP extensions and MCP servers (yes they're different) used by Claude desktop? If you're a Claude Enterprise customer you can configure these settings centrally and roll them out. This is separate from Claude Code though. Are you using this feature?
000
tuckner @johntuckner.me · 10/11/2025
Powerful new Detections are added to Secure Annex. These are already catching subtle exploits like unicode extension names that evade other filters, manipulated download counts, and combinations of suspicious signatures in code.
000
tuckner @johntuckner.me · 09/11/2025
Two of these Cursor extensions will compromise your device the second you hit install. Good luck!
011
tuckner @johntuckner.me · 07/11/2025
Check it out www.tines.com/whats-new/us...
000
tuckner @johntuckner.me · 07/11/2025
Ridiculously cool that Tines is able to connect to MCP servers now. Understand entirely what any of the browser or code extensions you use might actually be doing. Orchestrate your extension review process or check if "Hello Kitty - You Glow Girl Cute Live Wallpaper" is more than what it says.
110
tuckner @johntuckner.me · 07/11/2025
Right I should've included the execution part as well as the packaged decrypt tool with instructions.
110
tuckner @johntuckner.me · 07/11/2025
Idk folks this AI generated C2 code I found this week might have you shocked
110
tuckner @johntuckner.me · 05/11/2025
Ransomware has appeared in the VS Marketplace and makes me worry. Clearly created through AI, it makes many mistakes like including decryption tools in extension. If this makes it into the marketplace through, what impact would anything more sophisticated cause? secureannex.com/blog/ransomv...
secureannex.com
RansomVibing appears in VS Code extensions
Vibe coded ransomware has successfully been published to the VS Code extension marketplace
042