Security Platform for AI Agents | Knostic Blog

Knostic Research Team Blog

SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain

Knostic identified four VS Code extensions that reuse malicious code from the SaassyCode family. They reveal two distinct forms of reuse: one package ...

24 August 2026

[Read more

Analyzing Two Malicious VS Code Extensions Hidden Behind a WordPress Tool

Two VS Code extensions, published within days of each other, both marketed themselves as WordPress d...

21 July 2026

research findings

The Source Looked Clean. The Binary Wasn't.

Sample api-reactor.vsix — NoahBit.api-reactor v0.0.1 SHA-256 ca272b481f630635cd059f85321dbc7be372e75...

29 June 2026

research findings

Revoking Your Token Won't Save You: The VS Code Attack That Installs a Permanent GitHub Backdoor

The Attack That Survives Your Response When a developer discovers a compromised VS Code extension, t...

15 June 2026

research findings

SaassyCode Post-Disclosure Wave: Five New Extensions, 32,000+ Total Installs

Previous post:Update and Infect: How the SaassyCode Campaign Grew from Two Extensions to Nineteen →

11 June 2026

research findings

AI Coding Agent Governance Policies That Work

Fast Facts on AI Coding Agent Governance AI coding agent governance refers to the rules, roles, and ...

2 December 2025

AI data security