Kotaiba Alachkar

dblp:418/9704 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
4since 2021 · last 2026
0009-0002-5138-3833ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 4 since 2021
YearPublicationVenuePosition
2026 VSMEx: A Collection Tool and a Dataset of Malicious VS Code Extensions: Data/Toolset Paper
abstract
Visual Studio Code (VS Code) is one of the most widely used code editors, and its extension ecosystem has increasingly become a target for software supply chain attacks. Developing and validating effective detection techniques in this area requires ground-truth data with both benign and malicious samples. While benign samples are easy to obtain, no publicly available or continuously updated dataset exists for malicious VS Code extensions. To address this gap, we built VSMEx, a continuously updated dataset of malicious VS Code extensions derived from Microsoft's official malicious and removed lists. Over a deployment period of more than three months, VSMEx successfully captured 214 extensions, demonstrating the viability of our approach. In this work, we present an initial analysis of the resulting dataset and share the associated metadata and the list of flagged or removed extensions collected during this period. In addition, we provide controlled access to the dataset itself, facilitating further research and contributing to the security of the VS Code ecosystem. Note that VSMEx continues to operate, making the resulting dataset well suited for training and validation in continuous machine learning settings.
Kotaiba Alachkar, Dirk Gaastra, Olga Gadyatskaya, Eduardo Barbaro, Michel van Eeten, Yury Zhauniarovich
CODASPY1
2026 Abusing Cloud Services to Establish Covert Channels in Secure Enterprise Environments
Kotaiba Alachkar, Eduardo Barbaro, Cristiano Giuffrida, Michel van Eeten, Yury Zhauniarovich
EuroS&P1
2026 Dissecting Malicious VS Code Extensions: Characterization and Classification
Kotaiba Alachkar, Dirk Gaastra, Karlo Zanki, Marc Ohm, Eduardo Barbaro, Yury Zhauniarovich
SECRYPT (1)1
2025 EvilEDR: Repurposing EDR as an Offensive Tool
Kotaiba Alachkar, Dirk Gaastra, Eduardo Barbaro, Michel van Eeten, Yury Zhauniarovich
USENIX Security Symposium1