In this talk we expose how modern, browser-based IDEs (like VS Code and Cursor) have become the software supply chain's weakest link. The talk demonstrates how threat actors weaponize malicious extensions, 0-day vulnerabilities, and Chromium exploits to turn a developer's workspace into an enterprise backdoor - and delivers actionable insights for scaling IDE security.