Tech

VSCode extensions pulled over security risks, but millions of users have already installed

Share
Share


  • Security researchers found malicious code hiding in two VSCode extensions
  • Microsoft quickly pulled them and notifies users
  • The developer criticized Microsoft’s move, saying they were never consulted

Microsoft has pulled two popular VSCode extensions from its marketplace after finding malicious code hiding inside. However, the original developers don’t seem to be the culprits, and have slammed Microsoft for its harsh reaction which, they claim, caused more harm than good.

Two security researchers – Amit Assaraf and Itay Kruk – used a specialized scanner to analyze extensions in Visual Studio Marketplace, and have found obfuscated malicious code in “Material Theme – Free” and “Material Theme Icons – Free”, two extensions built by one Mattia Astorino (AKA equinusocio).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
When the school bell rings, the bandwidth drops: How post-15:40 internet surges affect UK broadband quality
Tech

When the school bell rings, the bandwidth drops: How post-15:40 internet surges affect UK broadband quality

Half of parents work after school, causing a broadband battle with streaming-addicted...

You can put Google Gemini right on your smartphone home screen – here’s how
Tech

You can put Google Gemini right on your smartphone home screen – here’s how

Google has launched Gemini home screen widgets for Android and iOS devices...

You can now fact check anybody’s post in WhatsApp – here’s how
Tech

You can now fact check anybody’s post in WhatsApp – here’s how

Perplexity AI’s new WhatsApp integration offers instant fact-checking without leaving the app...