In recent days, it has been reported that several Visual Studio Code extensions are exploiting a vulnerability that allows the reuse of package names that have been deleted. This issue has raised ...
Spread the loveVisual Studio Code, often simply called VSCode, has become the go-to code editor for developers worldwide. Its flexibility and powerful features make it a favorite among programmers.
Threat actors continue to probe Visual Studio Code's extension ecosystem, and a late November incident shows how quickly a trusted developer tool can be turned into a supply chain beachhead. In a ...
Treat this as an immediate security incident, CISOs advised; researchers say it’s one of the most sophisticated supply chain attacks they’ve seen, and it’s spreading. A month after a self-propagating ...
An unknown threat actor is deploying a large-scale, sophisticated cryptojacking campaign through a series of malicious extensions in Visual Studio Code, Microsoft’s lightweight source-code editor, ...
Two malicious extensions on Microsoft's Visual Studio Code Marketplace infect developers' machines with information-stealing malware that can take screenshots, steal credentials, crypto wallets, and ...