Malicious Repos & IDE Trust

    Opening a Folder Can Run Code

    Editor tasks, extensions and install scripts in unfamiliar projects can execute automatically. Use restricted mode.

    Developer & Technical SecurityDevelopers

    Illustrative scenario

    How It Looks in Real Life

    You open a cloned repository in your editor and accept “Trust the authors?”. A task configured to run on folder open starts a script in the background.

    Understand it

    How the Attack Works

    Editors can run configured tasks, debug settings and extension recommendations from a project folder. Workspace Trust exists to block these until you decide the folder is safe.

    Red flags

    Warning Signs

    • Trust prompts for projects from unknown sources.
    • Task or launch configuration files that run scripts automatically.
    • Recommended extensions you have never heard of.

    Safer habits

    What to Do Instead

    • 1Open unfamiliar repos in Restricted Mode and review configuration files first.
    • 2Inspect install scripts and build files before running them.
    • 3Use a separate VM or dev container for untrusted code.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: installed software or ran a command
    1. 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
    2. 2Report to IT or security and describe exactly what you ran or installed.
    3. 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
    4. 4From a different, trusted device, change passwords for accounts used on the affected machine.
    If you: exposed a token, key or secret
    1. 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
    2. 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
    3. 3Review provider logs for use of the key after the exposure time.

    Knowledge Check

    What Would You Do?

    Your editor asks whether you trust the authors of a repo shared in a public chat. What do you choose?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us