[HN Gopher] Malicious VSCode Marketplace extensions hid trojan i...
___________________________________________________________________
Malicious VSCode Marketplace extensions hid trojan in fake PNG file
Author : speckx
Score : 12 points
Date : 2025-12-11 20:59 UTC (2 hours ago)
(HTM) web link (www.bleepingcomputer.com)
(TXT) w3m dump (www.bleepingcomputer.com)
| peacebeard wrote:
| > Because threat actors find new ways to evade detection on
| public repositories used for software development, it is
| recommended that users inspect packages before installation,
| especially when the source is not a reputable publisher.
|
| Serious question: what is realistically meant by "inspect
| packages before installation" here? I assume they don't mean
| "review all the code in the packaged node_modules to find any
| trojans." Maybe "don't install plugins with packaged
| dependencies" but I'm not sure how common it is in this context.
|
| My takeaway will just be "continue to use the default VSCode
| theme."
___________________________________________________________________
(page generated 2025-12-11 23:01 UTC)