Bloom Security found that 677 VS Code Marketplace extension packs and 94 Open VSX packs contained references to extensions that did not exist, creating a supply-chain attack path through trusted ...
Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development ...
Threat actors are publishing clean extensions that later update to depend on hidden payload packages, bypassing marketplace checks and silently installing malware onto developers’ systems. Threat ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results