Live data from Hacker News

Malicious VSCode extensions with installs discovered

bleepingcomputer.com

1–10 of 15 posts

Re: Malicious VSCode extensions with installs discovered

#5
post #4

Strange that they use an example with a 192.168 address and say that it’s connecting to a cybercriminal’s server

Seems to be taken from https://medium.com/@amitassaraf/2-6-exposing-malicious-exten.... I doubt the writer of this article knows of any technical details and just carried over the mistake

Re: Malicious VSCode extensions with installs discovered

#7
post #2

Jeez, what a disaster. More and more it’s becoming clear that you cannot actually trust anyone else’s code unless you audit it yourself.

How can we live like this?

Nothing dependent on an honor system lasts long (in the US at least). Some bonehead always ruins the nice thing! Life with the inevitable bad actor is worse for everyone… but we manage.

Re: Malicious VSCode extensions with installs discovered

#8
Actual Medium post as shared here by the creator of the fake VSCode Extension:

We Hacked Multi-Billion $ Companies in 30 Minutes with a VSCode Extension

https://medium.com/@amitassaraf/the-story-of-extensiontotal-...

(https://news.ycombinator.com/item?id=40624000)

Re: Malicious VSCode extensions with installs discovered

#9
post #2

Jeez, what a disaster. More and more it’s becoming clear that you cannot actually trust anyone else’s code unless you audit it yourself.

How can we live like this?

What's old is new again.

https://en.m.wikipedia.org/wiki/Web_of_trust

Re: Malicious VSCode extensions with installs discovered

#10
post #6

> 1,283 with known malicious code (229 million installs) Not expecting that many. I sometimes randomly try interesting extensions out. Will not do this again. Should only install extensions recommended by Microsoft I guess. Maybe the same applies for browser extensions?

Please don't be a dev with access to things my security depends on.
Post reply on HN