[HN Gopher] Malicious VSCode Marketplace extensions hid trojan i...
       ___________________________________________________________________
        
       Malicious VSCode Marketplace extensions hid trojan in fake PNG file
        
       Author : speckx
       Score  : 12 points
       Date   : 2025-12-11 20:59 UTC (2 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | peacebeard wrote:
       | > Because threat actors find new ways to evade detection on
       | public repositories used for software development, it is
       | recommended that users inspect packages before installation,
       | especially when the source is not a reputable publisher.
       | 
       | Serious question: what is realistically meant by "inspect
       | packages before installation" here? I assume they don't mean
       | "review all the code in the packaged node_modules to find any
       | trojans." Maybe "don't install plugins with packaged
       | dependencies" but I'm not sure how common it is in this context.
       | 
       | My takeaway will just be "continue to use the default VSCode
       | theme."
        
       ___________________________________________________________________
       (page generated 2025-12-11 23:01 UTC)