Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
The classic VS Code is great and all, but these specialized forks are better for certain programming tasks ...
Security researchers found two AI-branded VS Code extensions with 1.5M installs that covertly send source code and files to ...
A new Visual Studio Code extension called Nogic sparked a wide-ranging Hacker News discussion, with commenters praising its ...
Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers.
Two VSCode extensions are harvesting sensitive data and sending it to China.
In a a robust Hacker News thread sparked by Jamf Threat Labs research, a VS Code team member defended the editor's Workspace ...
It's no less than a modern miracle ...
Two malicious VS Code extensions have exfiltrated code snippets, API keys, and proprietary algorithms from 1.5 million ...