Malicious VSCode extensions with millions of installs discovered
"Typosquatting the Dracula theme"
Mondjuk nem töltötték le olyan sokan, de azért volt találat szépen:
"The extension quickly gained traction, getting mistakenly installed by multiple high-value targets, including a publicly listed company with a $483 billion market cap, major security companies, and a national justice court network."
Ez az érdekesebb nekem:
"After the successful experiment, the researchers decided to dive into the threat landscape of the VSCode Marketplace, using a custom tool they developed named 'ExtensionTotal' to find high-risk extensions, unpack them, and scrutinize suspicious code snippets.
Through this process, they have found the following:
- 1,283 with known malicious code (229 million installs).
- 8,161 communicating with hardcoded IP addresses.
- 1,452 running unknown executables.
- 2,304 that are using another publisher's Github repo, indicating they are a copycat."
- Tovább (Malicious VSCode extensions with millions of installs discovered)
- 731 megtekintés