9.0.2

    MySQL

    Database Management for MySQL/MariaDB, PostgreSQL, Redis and ElasticSearch.

    Rank#-5755
    Publisher cweijanRegistry openvsx1,316,144Last scanned Sep 14, 2026, 06:44 AMRegistryHomepageGitHub
    Created
    7 years ago
    Last commit
    4 months ago
    Latest release
    4.7.05 years ago

    Security Findings

    34

    Hardcoded C2 with exfil/exec behavior

    MaliciousScanner

    Contacts a hardcoded public IP paired with download/eval/sensitive-access/upload

    Hardcoded C2 infrastructure3×

    SuspiciousScanner

    Hardcoded public IP address: 7.1.5.144

    Hardcoded public IP address: 7.1.6.123

    Hardcoded public IP address: 7.1.2.128

    Package registry name mismatch

    SuspiciousLineage

    npm name 'vscode-mysql-client2' != repo 'vscode-database-client'

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in out/extension.js: axios

    out/extension.js

    Hardcoded secrets/API keys8×

    SuspiciousScanner

    Secret Keyword: passw...****

    Secret Keyword: new_p...****

    Private Key: BEGIN...****

    Private Key: PuTTY...****

    Secret Keyword: strin...****

    Secret Keyword: ****

    Secret Keyword: dbcli...****

    Secret Keyword: funct...****

    out/extension.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: strin...****

    out/node_modules/tedious.js

    Hardcoded secrets/API keys2×

    SuspiciousScanner

    Secret Keyword: passw...****

    Secret Keyword: new_p...****

    out/webview/assets/getDialect-Cb7AiqG5.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: API K...****

    out/webview/assets/notify-DTNH_1b0.js

    Hardcoded secrets/API keys2×

    SuspiciousScanner

    Secret Keyword: strin...****

    Private Key: BEGIN...****

    out/node_modules/mongodb.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: Actua...****

    package.nls.es.json

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: Mettr...****

    package.nls.fr.json

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: Atual...****

    package.nls.pt-br.json

    Hardcoded secrets/API keys3×

    SuspiciousScanner

    Secret Keyword: mysql...****

    Secret Keyword: ER_MU...****

    Secret Keyword: ER_PA...****

    out/node_modules/mariadb.js

    Sensitive file access

    SuspiciousScanner

    Access to sensitive file: /etc/passwd

    Suspicious outbound hosts7×

    SuspiciousScanner

    Outbound URLs to non-allowlisted host(s): docs.neo4j.org, grpc.io

    Outbound URLs to non-allowlisted host(s): docs.snowflake.com, json-schema.org, vecta.io

    Outbound URLs to non-allowlisted host(s): database-client.com, dev.mysql.com, element-plus.org, icon-sets.iconify.design, tinypng.com, www.postgresql.org, www.svgrepo.com

    Outbound URLs to non-allowlisted host(s): jira.mariadb.org, jira.mongodb.org, mariadb.com, tools.ietf.org, vault.azure.net, www.mongodb.com

    Outbound URLs to non-allowlisted host(s): app.turso.tech, cdn.database-client.com, database-client.com, duckdb.org, element-plus.org, jdk.java.net, www.sqlite.org

    Outbound URLs to non-allowlisted host(s): database-client.com, jira.mongodb.org, mockjs.com, www.mongodb.com

    Outbound URLs to non-allowlisted host(s): [ffff::], api.tinify.com, app.database-client.com, app.snowflake.com, app.turso.tech, browser.database-client.com, cdn.database-client.com, click.database-cli...