Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Malicious VS Code extensions strike again.

Malicious VS Code extensions strike again.

Scheduled Pinned Locked Moved Uncategorized
infosecbreachcybersecuritygithubvscode
3 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • agnivesh@infosec.exchangeA This user is from outside of this forum
    agnivesh@infosec.exchangeA This user is from outside of this forum
    agnivesh@infosec.exchange
    wrote last edited by
    #1

    Malicious VS Code extensions strike again. I’ve lost track of how many times this has happened.

    X Cancelled | Verifying your request

    favicon

    (xcancel.com)

    #infosec #breach #cybersecurity #github #vscode

    mokey@cotorreo.fraggle-rock.orgM agnivesh@infosec.exchangeA 2 Replies Last reply
    0
    • agnivesh@infosec.exchangeA agnivesh@infosec.exchange

      Malicious VS Code extensions strike again. I’ve lost track of how many times this has happened.

      X Cancelled | Verifying your request

      favicon

      (xcancel.com)

      #infosec #breach #cybersecurity #github #vscode

      mokey@cotorreo.fraggle-rock.orgM This user is from outside of this forum
      mokey@cotorreo.fraggle-rock.orgM This user is from outside of this forum
      mokey@cotorreo.fraggle-rock.org
      wrote last edited by
      #2

      @agnivesh Friends don’t let friends use Visual Studio Code.

      1 Reply Last reply
      0
      • agnivesh@infosec.exchangeA agnivesh@infosec.exchange

        Malicious VS Code extensions strike again. I’ve lost track of how many times this has happened.

        X Cancelled | Verifying your request

        favicon

        (xcancel.com)

        #infosec #breach #cybersecurity #github #vscode

        agnivesh@infosec.exchangeA This user is from outside of this forum
        agnivesh@infosec.exchangeA This user is from outside of this forum
        agnivesh@infosec.exchange
        wrote last edited by
        #3

        Now is a good time to remind everyone that there has been an open request since 2018 to harden how VS Code extensions are run, and Microsoft has yet to address it

        Link Preview Image
        [Feature Request] Extension Permissions, Security Sandboxing & Update Management Proposal · Issue #52116 · microsoft/vscode

        I believe that Visual Studio Code should support some kind of "Extension Permission Management", complete with prompts, warnings, opt-in, and opt-out, similar to what has been supported for some time now with Chrome, Firefox, and other b...

        favicon

        GitHub (github.com)

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups