Security researchers have identified serious flaws in several widely used Visual Studio Code extensions that may allow attackers to access files or execute commands on developer machines. Together, the affected add-ons account for more than 100 million installations, making the potential impact significant. Because editor extensions interact directly with local projects, terminals, and network resources,…
Malicious VSCode extensions have infiltrated Microsoft’s official Visual Studio Code Marketplace and exposed developers to silent data theft. Attackers disguised the extensions as AI-powered coding assistants, then used them to monitor files, track activity, and exfiltrate sensitive project data without user awareness. The discovery raises serious concerns about extension security and the growing risk of…
Forked versions of the Visual Studio Code IDE expose developers to a growing supply-chain risk tied to extension recommendations. Security researchers warn that some forks suggest extensions that do not exist in trusted registries, which allows attackers to publish malicious packages under those names and trick users into installing them. The issue affects both traditional…
VSCode crypto-extensions are facing a major security threat. Cybercriminals linked to a group known as WhiteCobra have flooded Visual Studio Code Marketplace and OpenVSX with malicious extensions designed to steal cryptocurrency wallets, browser data, and login credentials. These rogue extensions imitate legitimate developer tools, tricking users into downloading malware that compromises their systems. WhiteCobra’s Strategy…