Security Platform for AI Agents | Knostic Blog
Knostic Research Team Blog
SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain
Knostic identified four VS Code extensions that reuse malicious code from the SaassyCode family. They reveal two distinct forms of reuse: one package ...
24 August 2026
[Read more
Analyzing Two Malicious VS Code Extensions Hidden Behind a WordPress Tool
Two VS Code extensions, published within days of each other, both marketed themselves as WordPress d...
21 July 2026
The Source Looked Clean. The Binary Wasn't.
Sample api-reactor.vsix — NoahBit.api-reactor v0.0.1 SHA-256 ca272b481f630635cd059f85321dbc7be372e75...
29 June 2026
Revoking Your Token Won't Save You: The VS Code Attack That Installs a Permanent GitHub Backdoor
The Attack That Survives Your Response When a developer discovers a compromised VS Code extension, t...
15 June 2026
SaassyCode Post-Disclosure Wave: Five New Extensions, 32,000+ Total Installs
Previous post:Update and Infect: How the SaassyCode Campaign Grew from Two Extensions to Nineteen →
11 June 2026
AI Coding Agent Governance Policies That Work
Fast Facts on AI Coding Agent Governance AI coding agent governance refers to the rules, roles, and ...
2 December 2025