you are viewing a single comment's thread
view the rest of the comments
[–] 39 points 2 years ago (1 child)

I believe they're referring to lower down in the article, where the researchers analyzed existing extensions on the marketplace:

After the successful experiment, the researchers decided to dive into the threat landscape of the VSCode Marketplace, using a custom tool they developed named 'ExtensionTotal' to find high-risk extensions, unpack them, and scrutinize suspicious code snippets.

Through this process, they have found the following:

  • 1,283 with known malicious code (229 million installs).
  • 8,161 communicating with hardcoded IP addresses.
  • 1,452 running unknown executables.
  • 2,304 that are using another publisher's Github repo, indicating they are a copycat.
  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (1 child)

    If you look at the code of one of the "malicious code", it hit a ... local IP, not a remote one.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 19 points 2 years ago (2 children)

    Does that mean the hacker is in my room??

  • source
  • parent
  • hideshow 4 child comments