Esc
IDE Extensions - T1176.002
(ATT&CK® Technique)
Definition
Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems. IDEs such as Visual Studio Code, IntelliJ IDEA, and Eclipse support extensions - software components that add features like code linting, auto-completion, task automation, or integration with tools like Git and Docker. A malicious extension can be installed through an extension marketplace (i.e., Compromise Software Dependencies and Development Tools) or side-loaded directly into the IDE.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.