Beehaw
  • Communities
  • Create Post
  • search
    Search
  • Login
  • Sign Up
 floofloof   ( @floofloof@lemmy.ca )  to Programming@programming.devEnglish · 2 years ago

Malicious VSCode extensions with millions of installs discovered

www.bleepingcomputer.com

external-link
message-square
16
link
fedilink
  • cross-posted to:
  • programming
156
external-link

Malicious VSCode extensions with millions of installs discovered

www.bleepingcomputer.com

 floofloof   ( @floofloof@lemmy.ca )  to Programming@programming.devEnglish · 2 years ago
message-square
16
link
fedilink
  • cross-posted to:
  • programming
A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to "infect" over 100 organizations by trojanizing a copy of the popular 'Dracula Official theme to include risky code. Further research into the VSCode Marketplace found thousands of extensions with millions of installs.
  •  eveninghere   ( @eveninghere@beehaw.org ) 
    link
    fedilink
    arrow-up
    2
    ·
    2 years ago

    You can’t trust extensions these days.

    •  Baldr   ( @balder1993@programming.dev ) 
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      Or anything that downloads code from an untrusted source…

      •  eveninghere   ( @eveninghere@beehaw.org ) 
        link
        fedilink
        arrow-up
        2
        ·
        2 years ago

        Gone are my student days where I downloaded whichever cool vim plugins

      •  soggy_kitty   ( @soggy_kitty@sopuli.xyz ) 
        link
        fedilink
        arrow-up
        1
        ·
        2 years ago

        “Untrusted source” is ambiguous fyi

Programming@programming.dev

programming@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programming@programming.dev

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 118 users / day
  • 563 users / week
  • 1.32K users / month
  • 3.76K users / 6 months
  • 445 local subscribers
  • 23.9K subscribers
  • 2.08K Posts
  • 17.6K Comments
  • Modlog
  • mods:
  •  snowe   ( @snowe@programming.dev ) 
  •  Ategon   ( @Ategon@programming.dev ) 
  •  MaungaHikoi   ( @MaungaHikoi@lemmy.nz ) 
  •  UlrikHD   ( @UlrikHD@programming.dev ) 
  • BE: 0.19.13
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code