Live data from Hacker News

GitHub confirms breach of 3,800 repos via malicious VSCode extension

bleepingcomputer.com

261–270 of 488 posts

Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension

#261

A good day not to be using Electronjs trash.

Electron has nothing to do with the exploit here. A Vim plugin would have just as much ability to run malware.

No one using vim will install the kind of extensions I found on the usual VS Code setup. And most don't even autoupdates.

Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension

#263

Vs code extensions have been terrifying for a long time. Such a wild and obvious attack vector. I'm constantly getting pop ups in vscode to install an extension because it recognizes a certain file type. It's 50-50 whether that extension is owned by a company or some random dev. Some of these have millions of installs and on first glance appear to be official company owned extensions. I'm at a point in my life where…

I don't use VSCode, but doesn't their plugin ecosystem indicate if the plugin is MSFT-approved?

Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension

#264
post #200

Earlier quoted context omitted.

Internet access. An editor extension does not need it.

All AI agent extensions disagree in unison.

It could request access to a specific domain which you can approve or deny

Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension

#267
post #263

Vs code extensions have been terrifying for a long time. Such a wild and obvious attack vector. I'm constantly getting pop ups in vscode to install an extension because it recognizes a certain file type. It's 50-50 whether that extension is owned by a company or some random dev. Some of these have millions of installs and on first glance appear to be official company owned extensions. I'm at a point in my life where…

I don't use VSCode, but doesn't their plugin ecosystem indicate if the plugin is MSFT-approved?

That just means the domain was verified which costs like 10 bucks.

Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension

#268

Earlier quoted context omitted.

The problem extends far beyond VS code. All extensions and executable code has the same problem. There was a case where Disney was hacked because an employee installed a BeamNG mod that had bundled malware. A company that wants to remain secure would have to employ strict restrictions on installing software. Only installing npm packages and plugins from an internal preapproved repo for example.

Funnily enough a lot of this "extension sprawl" is caused by the _difficulty_ of installing tools on locked down Windows machines. I recently moved to a locked down SoE and instead of being able to use regular tools (which require a lengthy negotiation process to install) I now use extensions for absolutely everything, _because_ they're not currently policed in the same way...

At my last workplace I was not allowed to install JSON viewer/prettier extension for my browser, but I was allowed to install VScode with random JSON plugins.

Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension

#269
post #262

Why does a company in GitHub's place allow employees to install random VSCode extensions?! That seems grossly irresponsible.

You're assuming they allow it, but it might be against policy.

I’m pretty sure there is an policy on their internal wiki saying you shouldn’t do that.

Problem is: most employees don’t care to read these. Although I’m sure something like this could have been checked for during commit.

Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension

#270
post #236

Earlier quoted context omitted.

I think the chart is still from the Steve Jobs era, who definitely was known to be a micromanager.

There’s an interview with someone talking about Steve having an extreme melt down rage about the header not being technically centered in one spot on the Apple page. I want to see his reaction trying to type a message on the iPhone keyboard from anytime in the past 7 years. Or navigate the random nonsensical grouping of stuff in settings that got so out of control they added a search bar or watch a pip video or reall…

And that's just the iPhone keyboard. The physical keyboards on MacBookPros are still terrible. I've had two of them where some of the keys shorted out or stopped working. Eventually, thinness has diminishing returns. I'd rather have a thicker/heavier keyboard where the keys don't die.
Post reply on HN