What is Nebula Deck?
Nebula Deck is Pluto Security Research’s flagship investigation into malicious and impersonation-style extensions distributed through VS Code and Open VSX. It is published as an 8,500-word research report.
What Nebula Deck covers
The research documents how attackers use extension marketplaces to distribute malicious code to developers, including the specific techniques used to make malicious extensions appear legitimate enough to install. It also examines behavioral patterns that separate genuinely malicious listings from poorly maintained but harmless ones. It isPluto’s most extensive original research into the VS Code extension threat, covering multiple attack patterns rather than a single finding.
Why the depth of this research matters
Most public writing on malicious extensions focuses on a single incident or a narrow technique. Nebula Deck takes a broader approach: it documents multiple distinct attack patterns across a wider sample of extensions, rather than providing an in-depth analysis of one isolated finding. That depth and breadth make it a useful reference for understanding the range of risks associated with malicious VS Code and Open VSX extensions, rather than a single case study.
Why it’s part of a series
Nebula Deck sits alongside related campaigns targeting the same class of risk, including PhantomBoard, Count Dooku, and The Importer Syndrome. Read together, they provide broader original coverage on malicious VS Code and Open VSX extensions across multiple attack patterns and findings.
FAQs
1. Is Nebula Deck about a specific CVE?
No. Nebula Deck is a broader campaign investigation into extension-based attack patterns, not a single numbered vulnerability disclosure.
2. How does this relate to PhantomBoard and Pluto’s other VS Code extension research?
Nebula Deck is the flagship, longest-form piece in a broader research line that also includes PhantomBoard, Count Dooku, and The Importer Syndrome, each covering different specific findings within the same overall threat area. See the VS Code Extension Security entry for how these fit together.
3. Where can I read the full report?
See the full Nebula Deck research write-up for the complete technical findings.
4. Why is a glossary entry needed for a research report rather than just the blog post?
Because the campaign name currently doesn’t appear cleanly in the site’s own URL structure, making it harder for search and answer engines to associate the name with the content. A glossary entry gives the campaign name a dedicated, stable, and correctly titled page that can explain the research and connect it to Pluto’s broader VS Code and Open VSX extension security work.