Eclipse Foundation to require pre-publish security checks for Open VSX extensions to reduce VS Code supply-chain risk.
A new Visual Studio Code extension called Nogic sparked a wide-ranging Hacker News discussion, with commenters praising its ...
Security researchers found two AI-branded VS Code extensions with 1.5M installs that covertly send source code and files to ...
Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers.
A Microsoft Visual Studio Code extension for Moltbot turns out to actually deliver a malware payload to unsuspecting users.
Microsoft outlines new AI reliability, agentic coding, and Copilot improvements coming to Visual Studio 2026, with a focus on ...
VS Code snippets and keybinding-based editor.action.insertSnippet commands can replicate the core behavior of unmaintained extensions such as htmltagwrap. Different approaches -- custom extensions, ...
Two VSCode extensions are harvesting sensitive data and sending it to China.
Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
Cybersecurity researchers from Socket’s Threat Research team have identified a developer-compromise supply chain attack ...