Tech

VSCode extensions pulled over security risks, but millions of users have already installed

Share
Share


  • Security researchers found malicious code hiding in two VSCode extensions
  • Microsoft quickly pulled them and notifies users
  • The developer criticized Microsoft’s move, saying they were never consulted

Microsoft has pulled two popular VSCode extensions from its marketplace after finding malicious code hiding inside. However, the original developers don’t seem to be the culprits, and have slammed Microsoft for its harsh reaction which, they claim, caused more harm than good.

Two security researchers – Amit Assaraf and Itay Kruk – used a specialized scanner to analyze extensions in Visual Studio Marketplace, and have found obfuscated malicious code in “Material Theme – Free” and “Material Theme Icons – Free”, two extensions built by one Mattia Astorino (AKA equinusocio).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
A new tool predicts when users will reject a new technology
Tech

A new tool predicts when users will reject a new technology

If you can predict that a new technology will not be adopted,...

This futuristic dual-screen laptop looks incredible, but one disappointing flaw might ruin it for power users
Tech

This futuristic dual-screen laptop looks incredible, but one disappointing flaw might ruin it for power users

Aura Ultrabook Dual 14″ Touch is perfect for presentations and scrolling through...

Two-actuator robot combines efficient ground rolling and spinning flight in one design
Tech

Two-actuator robot combines efficient ground rolling and spinning flight in one design

Weight breakdown of the ATOM prototype. The battery and the frame contribute...

How LLM architecture and training data shape AI’s position bias
Tech

How LLM architecture and training data shape AI’s position bias

Three types of attention masks and their corresponding directed graphs G used...