Github:
github.com/tylermorganw...
OpenVSX:
open-vsx.org/vscode/item?...
Github:
github.com/tylermorganw...
OpenVSX:
open-vsx.org/vscode/item?...
つかってね〜🥳✨
Marketplace
marketplace.visualstudio.com/items?itemNa...
OpenVSX
open-vsx.org/extension/ba...
GitHub
github.com/barineco/per...
つかってね〜🥳✨
Marketplace
marketplace.visualstudio.com/items?itemNa...
OpenVSX
open-vsx.org/extension/ba...
GitHub
github.com/barineco/per...
👉 open-vsx.org/extension/el...
#gamedev #vndev #naninovel
👉 open-vsx.org/extension/el...
#gamedev #vndev #naninovel
VS Code extensions get full access to your code and creds, and attackers have already slipped malware into VS Code Marketplace and OpenVSX.
So Socket now scans OpenVSX extensions before they ever hit your machine. 🔍⚡️
VS Code extensions get full access to your code and creds, and attackers have already slipped malware into VS Code Marketplace and OpenVSX.
So Socket now scans OpenVSX extensions before they ever hit your machine. 🔍⚡️
The releases occurred during a broader AI-powered attack targeting #OSS projects.
Full analysis ↓
socket.dev/blog/unautho...
The releases occurred during a broader AI-powered attack targeting #OSS projects.
Full analysis ↓
socket.dev/blog/unautho...
Dianyi Yang created an extension on OpenVSX that replicates the feature!
open-vsx.org/extension/kv...
Dianyi Yang created an extension on OpenVSX that replicates the feature!
open-vsx.org/extension/kv...
Give it a try here:
open-vsx.org/extension/un...
Give it a try here:
open-vsx.org/extension/un...
We love web devs!
secureannex.com/blog/these-v...
We love web devs!
secureannex.com/blog/these-v...
It also rotated creds for a bunch of developers that leaked their OpenVSX publishing tokens.
blogs.eclipse.org/post/mika%C3...
It also rotated creds for a bunch of developers that leaked their OpenVSX publishing tokens.
blogs.eclipse.org/post/mika%C3...
Install via OpenVSX (right in Positron)
GH:
github.com/tylermorganw...
Install via OpenVSX (right in Positron)
GH:
github.com/tylermorganw...
zed is the only thing I think is credible, and their problem is also extensions-related (in that they do not have enough of them)
zed is the only thing I think is credible, and their problem is also extensions-related (in that they do not have enough of them)
Read: hackread.com/glassworm-ma...
#Cybersecurity #SupplyChainAttack #Malware #VSCode #Malware
Read: hackread.com/glassworm-ma...
#Cybersecurity #SupplyChainAttack #Malware #VSCode #Malware
www.bleepingcomputer.com/news/securit...
www.bleepingcomputer.com/news/securit...
Glassworm actually seems to be the only active campaign right now on openvsx (or whatever else is going on is hiding it reaaaal good. Though these are 10mb+ packages so who knows right)
The rest are just one offs.
socket.dev/supply-chain...
Glassworm actually seems to be the only active campaign right now on openvsx (or whatever else is going on is hiding it reaaaal good. Though these are 10mb+ packages so who knows right)
The rest are just one offs.