Repository navigation
First public release.
Scans a VS Code workspace the moment you open it for PolinRider / GlassWorm supply-chain malware, lets you review and delete what it finds, and checks that VS Code and your Node toolchain have not been patched.
Detection is content-based, not extension-based. The incident this was written for hid JavaScript inside a whitespace-padded fa-solid-400.woff2 launched by a runOn: folderOpen task — invisible to any scanner that trusts the file extension.
Highlights
- Magic-byte verification for 15 binary types
- 20 IOC rules for the loader: victim tags,
app-vscode-eval,inzartifacts, C2 paths, the stage-2 XOR key, build markers folderOpentask and npm lifecycle hook checks- Trojan-Source Unicode detection
- Editor and toolchain integrity for VS Code, npm, yarn, pnpm and Claude Code
- Review-and-delete cleanup with a per-file checklist and a SHA-256 record
- Deep Scan covering
node_modulesand vendored code - Four-layer rule merge with glob allow-lists
- Zero runtime dependencies
See the changelog for the full list.
Install: download byteguard-1.0.0.vsix below, then code --install-extension byteguard-1.0.0.vsix