Eclipse Foundation to require pre-publish security checks for Open VSX extensions to reduce VS Code supply-chain risk.
Hackers have already published a fake Visual Studio Code extension that impersonates the assistant under its former name, ...
Cybersecurity researchers from Socket’s Threat Research team have identified a developer-compromise supply chain attack targeting macOS users, where ...
GlassWorm malware is expanding to open source platforms, targeting macOS users with infostealers.
A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems.
The classic VS Code is great and all, but these specialized forks are better for certain programming tasks ...
A compromised Open VSX publisher account was used to distribute malicious extensions in a new GlassWorm supply chain attack.
A Microsoft Visual Studio Code extension for Moltbot turns out to actually deliver a malware payload to unsuspecting users.
Security researchers found two AI-branded VS Code extensions with 1.5M installs that covertly send source code and files to ...
Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers.
Microsoft is urging employees to use Claude Code alongside GitHub Copilot, signaling a broader multi-tool AI coding strategy.
Microsoft has released the Copilot Studio extension for Visual Studio Code to general availability, enabling teams to build, ...