6 ms·
Microsoft were very quick to highlight their extensions being safer after this. https://x.com/code/status/1943720372307665033?s=46 https://x.com/code/status/19
by riv991 1y ago
Microsoft were very quick to highlight their extensions being safer after this.
https://x.com/code/status/1943720372307665033?s=46 https://x.com/code/status/1943720372307665033?s=46
- the_mitsuhiko 1y agoUnfortunately the marketplace ecosystem is why I went back to VSCode from Cursor. I'm a bit upset by this because I don't quite appreciate that Microsoft has a closed ecosystem for the marketplace and does not open it to Cursor but the reality is, that Open VSX does not have all extensions and little vetting.
- notpushkin 1y ago> Open VSX does not have all extensions This can be solved quite easily for open source extensions: https://github.com/EclipseFdn/open-vsx.org/wiki/Auto-Publishing-Extensions https://github.com/EclipseFdn/open-vsx.org/wiki/Auto-Publish... Vetting however is trickier. I hope Cursor can fund this effort!
- worble 1y agoAnd yet, this entire class of abuse is only possible because Microsoft refuse to implement any kind of permission management or sandboxing for extensions. https://github.com/microsoft/vscode/issues/52116 https://github.com/microsoft/vscode/issues/52116
- rs186 1y agoSecond this. As a vscode extension author, I am scared by the power I have. I am not at all surprised by what happened in this story.
- delusional 1y agoPeople better remember that tweet the next time somebody finds another malicious extension on their marketplace.
- Quarrel 1y agoand yet, there are many malware extensions per day that get through: https://github.com/microsoft/vsmarketplace/blob/main/RemovedPackages.md https://github.com/microsoft/vsmarketplace/blob/main/Removed...
- jowea 1y ago2 seconds? That wasn't the team then, it must have failed some automated filter.
- IshKebab 1y agoWell this was an extremely unsophisticated attack. The malware wasn't hidden and they didn't even bother to actually copy the real extension. If I were doing this I would copy the real extension, give it a name that made it sound official but in the README say it is a tweaked version with some improvements or whatever. Also actually add some improvements, but hide the malware in those changes. Good luck finding that. (brb going to try this)
- raincole 1y agoThe whole thing worked only because they gamed open-vsx ranking algorithm.