<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Malicious VS Code extensions strike again.]]></title><description><![CDATA[<p>Malicious VS Code extensions strike again. I’ve lost track of how many times this has happened.</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://xcancel.com/i/status/2056949168208552080">
 X Cancelled | Verifying your request
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://xcancel.com/i/status/2056949168208552080" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://xcancel.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(xcancel.com)</span></p>
</a>
</div></p><p><a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/breach" rel="tag">#<span>breach</span></a> <a href="https://infosec.exchange/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/github" rel="tag">#<span>github</span></a> <a href="https://infosec.exchange/tags/vscode" rel="tag">#<span>vscode</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/adb4e4b0-05ed-4ff4-8ec8-1caf7790723e/malicious-vs-code-extensions-strike-again.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 10:38:22 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/adb4e4b0-05ed-4ff4-8ec8-1caf7790723e.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 06:50:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Malicious VS Code extensions strike again. on Wed, 20 May 2026 07:45:52 GMT]]></title><description><![CDATA[<p>Now is a good time to remind everyone that there has been an open request since 2018 to harden how VS Code extensions are run, and Microsoft has yet to address it</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://github.com/microsoft/vscode/issues/52116" title="[Feature Request] Extension Permissions, Security Sandboxing & Update Management Proposal · Issue #52116 · microsoft/vscode">
<img src="https://opengraph.githubassets.com/2ea0f8dccea6dcef88c9e491c0ed5326a967a44b7a32471c9dcd3b58689cd659/microsoft/vscode/issues/52116" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://github.com/microsoft/vscode/issues/52116">
[Feature Request] Extension Permissions, Security Sandboxing & Update Management Proposal · Issue #52116 · microsoft/vscode
</a>
</h5>
<p class="card-text line-clamp-3">I believe that Visual Studio Code should support some kind of "Extension Permission Management", complete with prompts, warnings, opt-in, and opt-out, similar to what has been supported for some time now with Chrome, Firefox, and other b...</p>
</div>
<a href="https://github.com/microsoft/vscode/issues/52116" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://github.githubassets.com/favicons/favicon.svg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0">GitHub <span class="text-secondary">(github.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/agnivesh/statuses/116605789959904982</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/agnivesh/statuses/116605789959904982</guid><dc:creator><![CDATA[agnivesh@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 07:45:52 GMT</pubDate></item><item><title><![CDATA[Reply to Malicious VS Code extensions strike again. on Wed, 20 May 2026 06:56:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/agnivesh%40infosec.exchange" rel="nofollow noreferrer noopener">@<span>agnivesh</span></a></span> Friends don’t let friends use Visual Studio Code.</p>]]></description><link>https://board.circlewithadot.net/post/https://cotorreo.fraggle-rock.org/users/mokey/statuses/01KS22QVZR2BE3B7S1D998WQP5</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cotorreo.fraggle-rock.org/users/mokey/statuses/01KS22QVZR2BE3B7S1D998WQP5</guid><dc:creator><![CDATA[mokey@cotorreo.fraggle-rock.org]]></dc:creator><pubDate>Wed, 20 May 2026 06:56:30 GMT</pubDate></item></channel></rss>