securityvisual-studio-codeprivacy

How to disable internet access for a particular vscode extension you don't trust


VS Code is becoming more and more awesome all along with its crazy extensions, but with all that flexibility and awesomeness comes security and privacy risks.

Thus my question if at all it is possible to block a specific extension from accessing internet.


Solution

  • The answer appears to be no, you can't block extension network access:

    Relatedly, one might ask if there is any system in place to detect or prevent malicious extension behavior. Again the answer seems to be no:

    Overall, I find this a scary situation. I do a few things to try to protect myself:

    2024-06-09: A new service called ExtensionTotal (with which I have no affiliation) purports to check extensions for signs of malicious intent. They claim in a 2024-06-02 blog post to have found ~1000 published extensions with known malicious code, and ~150 that were flagged by VirusTotal. I've only briefly tried it, so who knows, but at least someone seems to be taking the problem seriously even if MS isn't.