Threat dossier · P1
Malicious extensions and marketplace fraud
AI-era development installs extensions and automation by default, so one popular trojanized listing can silently harvest material from thousands of machines while looking like a legitimate tool.
Direct answer
What is malicious extensions and marketplace fraud?
Malicious extensions and marketplace fraud place trojanized editor extensions, plugins, or CI actions inside trusted marketplaces, harvesting source code, prompts, and credentials from every developer who installs them.
Coverage statements below are limited to the current HOL Guard support contract and do not imply universal model or harness protection.
Representative attack path
Defensive model only. This sequence omits weaponized payloads and is not attributed to a specific incident unless a source explicitly says so.
Step 1
A trojanized extension, plugin, or workflow action is published to a trusted marketplace.
Step 2
Developers install it because the listing and publisher look legitimate.
Step 3
The extension harvests code, prompts, or credentials, or opens remote access.
Step 4
Exfiltrated material is reused for further access or resale.
Coverage boundary
What this control can cover
- Runtime actions an installed agent tool attempts on supported action surfaces remain policy-evaluated.
- Install intents for supported package and artifact paths can be routed to review.
What it does not prove or prevent
- Vetting or removing marketplace listings; that belongs to the marketplace operator.
- Harvesting performed inside extensions that never triggers a Guard-visible action.
Policy pattern
Policy pattern for malicious extensions and marketplace fraud
Keep untrusted context or overbroad autonomy from becoming unconditional execution authority on supported action surfaces.
Use when: AI-era development installs extensions and automation by default, so one popular trojanized listing can silently harvest material from thousands of machines while looking like a legitimate tool.
Decision pattern
- Identify the trust boundary and consequential action class.
- Apply least privilege and the narrowest supported policy.
- Require review for sensitive or ambiguous actions.
- Preserve only redacted, versioned evidence needed to reproduce the decision.
Limitations
- Vetting or removing marketplace listings; that belongs to the marketplace operator.
- Harvesting performed inside extensions that never triggers a Guard-visible action.
If you suspect prompt injection
Step 1
Response 1
Uninstall the extension and revoke its granted permissions or tokens.
Step 2
Response 2
Rotate credentials and sessions exposed to the extension.
Step 3
Response 3
Review what the extension accessed and where it sent data.
Step 4
Response 4
Check other machines for the same listing.
Sources and mappings
Related dossiers
Neighboring threat classes that share attack paths or trust boundaries with this dossier.