Security researchers found two AI-branded VS Code extensions with 1.5M installs that covertly send source code and files to ...
Two malicious VS Code extensions have exfiltrated code snippets, API keys, and proprietary algorithms from 1.5 million ...
Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers.
The malicious activity is targeting organizations with software development teams that rely on VS Code and third-party extensions and have access to production systems, cloud resources, or digital ...
Eclipse Foundation to require pre-publish security checks for Open VSX extensions to reduce VS Code supply-chain risk.
Two VSCode extensions are harvesting sensitive data and sending it to China.
Visual Studio Code (VSCode) allows you to use extensions to make development more convenient. It has been reported that an extension that distributes ransomware has been published on the Visual Studio ...
GlassWorm malware is expanding to open source platforms, targeting macOS users with infostealers.
Fake AI coding assistants for VS Code, disguised as ChatGPT extensions, infected over 1.5 million developers with spyware.