Live data from Hacker News

Malicious VSCode extensions with more than 45k installs

blog.checkpoint.com

101–110 of 191 posts

Re: Malicious VSCode extensions with more than 45k installs

#101

Earlier quoted context omitted.

Name squatting always betrays malicious intent. No benefit of the doubt is owed to anyone practicing it.

Before you go down this rabbit hole, consider that many extensions are slight forks of others. There isn't always malicious intent. Just people who try to extend the extensions and publish them without knowing otherwise. For example go look at any popular "Hello world" type of extension and you'll see many results of extensions in this definition of "name squatting". i.e. https://marketplace.visualstudio.com/search?t…

When you add telemetry to a fork of a thing that didn't previously have telemetry, you don't deserve the benefit of doubt. The original didn't need telemetry, so neither does your fork. Anybody who does this should be assumed malicious.

And telemetry for a fucking color theme? You've got shitting me. Whoever did this is a Grade-A scumbag. It didn't happen by accident and there is no possible benign motivation for it. I hope somebody has reported this to the FBI and other relevant authorities.

Re: Malicious VSCode extensions with more than 45k installs

#102
post #19

Capabilities-based security prevents these supply chain attacks! (Even though in this case most of the downloads were of packages including unwanted telemetry and not something more dangerous.) “…And now if a [color theme] wants to read your data and send it to a server, it needs a filesystem capability and a network capability. It should be an obvious red flag if a [theming addon] were to ask for those dependencies.…

Yeah, android tried this initially with the permissions system. But literally every app requested every permission and it became completely useless. As a user, you have no way of meaningfully using this info.

If there was a permission dialog with boxes I would gladly check or uncheck them because nowadays I need to write bash scripts, create separate users or build containers for every third-party app. Why doesn't OS include necessary tools?

Re: Malicious VSCode extensions with more than 45k installs

#103
post #13

This article is a good example of how to write a misleading headline. They found 3 extensions, one of which has 45k downloads (because it name squats on a popular package), and another with 1000 installs. The 45k dowload extension (Darcula Dark) collects some data that I would define as telemetry, and the python-vscode extension which is clearly trying to hide what it's doing. Now, whether you define telemetry as mal…

Woah, that's a narrow view. Name/typo-squatting in inherently malicious as there's intent to deceive. It doesn't matter what code is _currently_ present and that can change at any time. Besides, think about how you'd maliciously use that telemetry. If the author sees installations coming from intuit.com (for example) then they know they are one auto-update away from having a foothold on a company network with tons of…

This is my thinking exactly. If you put exploit code in there in day one, you are likely to be found out quickly. But if you wait until you detect a valuable target, test the waters with a non-malicious update, then you can probably distribute the malicious update to run in a targeted fashion, perhaps even rolling it back shortly after to reduce later forensic investigation.

We need to stop treating our dev tools like they are trusted. They are not, and they rely more and more on networks of even less trustworthy code. That VSCOde doesn’t have a proper sandbox or TCB for its plugins is pretty damning.

Re: Malicious VSCode extensions with more than 45k installs

#104

Earlier quoted context omitted.

Users here are experienced developers, so I think it's not such a big deal. In context, a theme should never need network or file storage access, so you could upfront block those for that type of extension. You can also have policies like "network access is okay but file system and network access together needs approval".

I find I very quickly tire of having to think about this. You think "A theme shouldn't require file storage access" and then spend an hour looking up why it does and find out there is actually some strange but totally legitimate reason for it. And every time that happens, you lose a little bit of will to care about what permissions something requested. There used to be a period where many android apps would explain i…

> You think "A theme shouldn't require file storage access" and then spend an hour looking up why it does and find out there is actually some strange but totally legitimate reason for it

No. You think it is suspicious and install another theme that doesn't request anything.

Re: Malicious VSCode extensions with more than 45k installs

#105

Earlier quoted context omitted.

Name squatting always betrays malicious intent. No benefit of the doubt is owed to anyone practicing it.

Before you go down this rabbit hole, consider that many extensions are slight forks of others. There isn't always malicious intent. Just people who try to extend the extensions and publish them without knowing otherwise. For example go look at any popular "Hello world" type of extension and you'll see many results of extensions in this definition of "name squatting". i.e. https://marketplace.visualstudio.com/search?t…

But it does imply a trust and quality issue with the VSCode marketplace.

Combined with the lack of a proper sandbox or TCB for plugins, having an untrustworthy “marketplace” makes VSCode sound like a disaster waiting to be installed.

Re: Malicious VSCode extensions with more than 45k installs

#106

Earlier quoted context omitted.

Before you go down this rabbit hole, consider that many extensions are slight forks of others. There isn't always malicious intent. Just people who try to extend the extensions and publish them without knowing otherwise. For example go look at any popular "Hello world" type of extension and you'll see many results of extensions in this definition of "name squatting". i.e. https://marketplace.visualstudio.com/search?t…

But it does imply a trust and quality issue with the VSCode marketplace. Combined with the lack of a proper sandbox or TCB for plugins, having an untrustworthy “marketplace” makes VSCode sound like a disaster waiting to be installed.

That's an opinion.

Another opinion is that there is plenty of crap on every registry and some are better at surfacing and cleaning up than others.

Similar to the US Navy and ships that are rust-free versus those battling rust. It doesn't affect the performance of those ships, just the perception. Left on for too long could eat away the actual integrity.

Not all problems are the registry's to burden. Trust and quality decisions are very individual for example. There's no same definition used between two people.

Re: Malicious VSCode extensions with more than 45k installs

#107

Article disingenuously wraps a couple extensions that seem to be “actually” malicious (secret stealing), with one that has a lot of installs and is “HN-malicious” (collects telemetry) for a striking headline. That said, malicious code in VS Code extensions is a problem. I wonder if a GPT could be helpful here. The existing internal systems for detecting malicious code seem lacking.

"HN-malicious"

Hehe. We could probably come up with a dozen similar HN specific adjectives.

Re: Malicious VSCode extensions with more than 45k installs

#108
post #55

Earlier quoted context omitted.

Users here are experienced developers, so I think it's not such a big deal. In context, a theme should never need network or file storage access, so you could upfront block those for that type of extension. You can also have policies like "network access is okay but file system and network access together needs approval".

Why are you assuming most VSCode users are "experienced developers"? I would think quite the contrary, as the younger crowd is probably much more likely to be using it than more experienced developers.

Fair enough. I think we can agree that the average VS code developer is more technically savvy than the average Android user?

Re: Malicious VSCode extensions with more than 45k installs

#109
post #78

Earlier quoted context omitted.

Indeed. Professional woodworking equipment can also cut you, but that’s a risk we accept as we know their developers also care more about providing a tool that works and can be used responsibly by trained professionals. Yes we could insist everyone only hands us straight jackets in padded rooms, but I’m not sure that’d be a good thing.

For over 20 years now, professional woodworkers have had SawStops, devices that literally use an explosive charge to ram a block of aluminum into the blade of a table saw when it detects that the blade is touching something that might be a human body part. These are $50+ devices that destroy themselves on use (and often destroy the $50+ blade they’re used on), they have a high false positive rate, and yet they’re sti…

Not something you’ll find in any professional cabinetry shop. But you’re welcome to use Notepad for all your coding.

Re: Malicious VSCode extensions with more than 45k installs

#110
post #19

Capabilities-based security prevents these supply chain attacks! (Even though in this case most of the downloads were of packages including unwanted telemetry and not something more dangerous.) “…And now if a [color theme] wants to read your data and send it to a server, it needs a filesystem capability and a network capability. It should be an obvious red flag if a [theming addon] were to ask for those dependencies.…

Yes! Sadly, today nobody seem to care about the principle of least privileges. Take Linux as an example: every program you install gets full access to the system, and gets thousands of privileges it doesn't need. If your PDF reader is vulnerable, it will have both access to your SSH keys and to the Internet to upload them (and if you block Internet access for a PDF reader, it still can send the data by connecting to…

Question: do snaps or similar tech in the distros help with this?
Post reply on HN