▲ 235 ▼ Malicious VSCode extensions with millions of installs discovered (www.bleepingcomputer.com) submitted 2 years ago by floofloof@lemmy.ca to c/programming@programming.dev 53 comments fedilink hide all child comments
[–] Skydancer@pawb.social 12 points 2 years ago (1 child) Except their summary is wrong. The researchers went on to search other extensions for known malicious code, and found it in thousands of extensions with tens of millions of total installs. permalink fedilink source parent hideshow 2 child comments replies: [–] Kuinox@lemmy.world -4 points 2 years ago (1 child) I hopped people here would notice that their "malicious code" detection is totally bogus when the malicious code highlighted hit a local IP address. permalink fedilink source parent hideshow 2 child comments replies: [–] Skydancer@pawb.social 2 points 2 years ago (1 child) Good point. That was in the "static IP" category and not counted in the 200+ million install "malicious code" category, though. It could be a warning sign of false positives, but the example was such a small snippet it could also be opening after a VPN is established. That example was supposedly part of code that opens a connection for shell access from the other end, but without more details it's not really possible to say. permalink fedilink source parent hideshow 2 child comments replies: [–] Kuinox@lemmy.world -1 points 2 years ago Tons of devtools summons cmd.exe and do networks. Their claim is that more than 10% of the vscode marketplate is malicious package (i just divided the number of extensions they says is malicious, by the number of extensions) permalink fedilink source parent
[–] Kuinox@lemmy.world -4 points 2 years ago (1 child) I hopped people here would notice that their "malicious code" detection is totally bogus when the malicious code highlighted hit a local IP address. permalink fedilink source parent hideshow 2 child comments replies: [–] Skydancer@pawb.social 2 points 2 years ago (1 child) Good point. That was in the "static IP" category and not counted in the 200+ million install "malicious code" category, though. It could be a warning sign of false positives, but the example was such a small snippet it could also be opening after a VPN is established. That example was supposedly part of code that opens a connection for shell access from the other end, but without more details it's not really possible to say. permalink fedilink source parent hideshow 2 child comments replies: [–] Kuinox@lemmy.world -1 points 2 years ago Tons of devtools summons cmd.exe and do networks. Their claim is that more than 10% of the vscode marketplate is malicious package (i just divided the number of extensions they says is malicious, by the number of extensions) permalink fedilink source parent
[–] Skydancer@pawb.social 2 points 2 years ago (1 child) Good point. That was in the "static IP" category and not counted in the 200+ million install "malicious code" category, though. It could be a warning sign of false positives, but the example was such a small snippet it could also be opening after a VPN is established. That example was supposedly part of code that opens a connection for shell access from the other end, but without more details it's not really possible to say. permalink fedilink source parent hideshow 2 child comments replies: [–] Kuinox@lemmy.world -1 points 2 years ago Tons of devtools summons cmd.exe and do networks. Their claim is that more than 10% of the vscode marketplate is malicious package (i just divided the number of extensions they says is malicious, by the number of extensions) permalink fedilink source parent
[–] Kuinox@lemmy.world -1 points 2 years ago Tons of devtools summons cmd.exe and do networks. Their claim is that more than 10% of the vscode marketplate is malicious package (i just divided the number of extensions they says is malicious, by the number of extensions) permalink fedilink source parent