50
submitted 4 months ago by neme@lemm.ee to c/vscode@programming.dev
top 3 comments
sorted by: hot top controversial new old
[-] Deebster@programming.dev 22 points 4 months ago* (last edited 4 months ago)

I'd like to see permissions in VSCode plugins, so e.g. I could see that a plugin x can't touch the filesystem or internet and is therefore more likely to be benign.

[-] KazuyaDarklight@lemmy.world 12 points 4 months ago

"A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to "infect" over 100 organizations by trojanizing a copy of the popular 'Dracula Official theme to include risky code. Further research into the VSCode Marketplace found thousands of extensions with millions of installs."

[-] towerful@programming.dev 2 points 4 months ago

The plugin is called "Darcula Official" btw.

There is a more generic theme (for multiple applications) called Dracula.
JetBrains IDE has a theme called Darcula, and there are vscode themes on the marketplace that implement this.

So, it's more than just a typosquat

this post was submitted on 09 Jun 2024
50 points (100.0% liked)

VS Code

784 readers
10 users here now

founded 1 year ago
MODERATORS