That article is awful...
The original post it's hacking is better: https://medium.com/@amitassaraf/2-6-exposing-malicious-extensions-shocking-statistics-from-the-vs-code-marketplace-cf88b7a7f38f
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
That article is awful...
The original post it's hacking is better: https://medium.com/@amitassaraf/2-6-exposing-malicious-extensions-shocking-statistics-from-the-vs-code-marketplace-cf88b7a7f38f
Medium's initial no-account view is awful though:
I always found it weird how people are willing to install obscure extensions just like that. For any program that supports them. This doesn't surprise me at all.
That being said I'll go recheck the few I have installed...
I don't think I realized that the extensions could contain code since most of them are just doing syntax highlighting.
You obviously haven't seen the platformio extension.
It's a beast, turns VSCode into an embedded IDE and programmer for loads of different microchips
Yeah I'm not using anything like that. Bit irresponsible of MS to not audit this stuff, then. Lots of businesses allowing users to install vs code extensions freely even if they're otherwise restricted for software installs.
There was also recently something similar with ComfyUI, where an extensions was embedded with a malware.