Skip to content

Conversation

@kineticsquid
Copy link
Collaborator

  • I have read the note above about PRs contributing or fixing extensions
  • I have tried reaching out to the extension maintainers about publishing this extension to Open VSX (if not, please create an issue in the extension's repo using this template).
  • This extension has an OSI-approved OSS license (we don't accept proprietary extensions in this repository)

Description

This is to remove potential malware extension "Anthropic.claude-code".

@filiptronicek filiptronicek merged commit b79a038 into EclipseFdn:master Aug 13, 2025
1 of 2 checks passed
@erikolofsson
Copy link

This broke the legitimate Claude Code extension that is installed by the claude command line tool.

EclipseFdn/open-vsx.org#4163

@kineticsquid
Copy link
Collaborator Author

@erikolofsson I'm sorry, we received a report of malware on this. I attempted to reach out to the Anthropic team, but was unsuccessful. Can you reach out directly to me at [email protected].

@erikolofsson
Copy link

I'm not with Anthropic, so it's probably best to try to reach out to them again. Did you try @igorkofman that claimed the namespace?

@kineticsquid
Copy link
Collaborator Author

Yeah, that's what I tried. It is August though. More importantly, you'd confirm that the extension, Anthropic.claude-code, was legitimate?

@erikolofsson
Copy link

I don't know about the extension that was on Open VSX, as the extension is installed by the claude tool:
https://docs.anthropic.com/en/docs/claude-code/ide-integrations

So basically what happens is that the tool installs the extension automatically, then every 60 seconds VS code checks if the extension is in the malicious list and uninstalls it again.

@kineticsquid
Copy link
Collaborator Author

@erikolofsson Thanks, I was going to ask you to open a GH issue on this. Let's take the discussion there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants