A malicious extension was published on Microsoft’s official VS Code marketplace, and was able to remain there for some time ...
Cybersecurity researchers have flagged a malicious Visual Studio Code (VS Code) extension with basic ransomware capabilities ...
A published VS Code extension didn't hide the fact that it encrypts and exfiltrates data and also failed to remove obvious signs it was AI-generated.
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...
Researchers say the malware was in the repository for two weeks, advise precautions to defend against malicious packages.