Threat dossier · P1

Malicious extensions and marketplace fraud

AI-era development installs extensions and automation by default, so one popular trojanized listing can silently harvest material from thousands of machines while looking like a legitimate tool.

Direct answer

What is malicious extensions and marketplace fraud?

Malicious extensions and marketplace fraud place trojanized editor extensions, plugins, or CI actions inside trusted marketplaces, harvesting source code, prompts, and credentials from every developer who installs them.

Coverage statements below are limited to the current HOL Guard support contract and do not imply universal model or harness protection.

Copied text includes the canonical source and review date.
Reviewed Reviewer: HOL Guard EngineeringReview cadence: 30 days

Representative attack path

Defensive model only. This sequence omits weaponized payloads and is not attributed to a specific incident unless a source explicitly says so.

  1. Step 1

    A trojanized extension, plugin, or workflow action is published to a trusted marketplace.

  2. Step 2

    Developers install it because the listing and publisher look legitimate.

  3. Step 3

    The extension harvests code, prompts, or credentials, or opens remote access.

  4. Step 4

    Exfiltrated material is reused for further access or resale.

Coverage boundary

What this control can cover

  • Runtime actions an installed agent tool attempts on supported action surfaces remain policy-evaluated.
  • Install intents for supported package and artifact paths can be routed to review.

What it does not prove or prevent

  • Vetting or removing marketplace listings; that belongs to the marketplace operator.
  • Harvesting performed inside extensions that never triggers a Guard-visible action.

Policy pattern

Policy pattern for malicious extensions and marketplace fraud

Keep untrusted context or overbroad autonomy from becoming unconditional execution authority on supported action surfaces.

Use when: AI-era development installs extensions and automation by default, so one popular trojanized listing can silently harvest material from thousands of machines while looking like a legitimate tool.

Decision pattern

  1. Identify the trust boundary and consequential action class.
  2. Apply least privilege and the narrowest supported policy.
  3. Require review for sensitive or ambiguous actions.
  4. Preserve only redacted, versioned evidence needed to reproduce the decision.

Limitations

  • Vetting or removing marketplace listings; that belongs to the marketplace operator.
  • Harvesting performed inside extensions that never triggers a Guard-visible action.

If you suspect prompt injection

  1. Step 1

    Response 1

    Uninstall the extension and revoke its granted permissions or tokens.

  2. Step 2

    Response 2

    Rotate credentials and sessions exposed to the extension.

  3. Step 3

    Response 3

    Review what the extension accessed and where it sent data.

  4. Step 4

    Response 4

    Check other machines for the same listing.

Sources and mappings

Neighboring threat classes that share attack paths or trust boundaries with this dossier.