DEV Machine Guard has expanded its capabilities to scan IDE extensions across multiple platforms including VS Code, Cursor, JetBrains IDEs, Android Studio, and more. This update allows organizations to manage a unified inventory and assesses risk via a Security Score. Key motivations include addressing recent security incidents involving IDE supply chain attacks, where compromised extensions have led to significant vulnerabilities.
The tool provides comprehensive visibility for security teams, enabling them to track installed extensions across different IDEs and take actions against risks like typosquatting and known compromises. Upcoming features include extension allowlists and cooldown periods for new versions. Users can start using the updated capabilities with an automatic scan after updating the tool.