Friday, 27 March 2026

Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks

iT4iNT SERVER Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX's pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry.
"The pipeline had a single boolean return value that meant both 'no scanners are configured' and 'all scanners failed to run,'" Koi VDS VPS Cloud


http://dlvr.it/TRkhNJ

No comments:

Post a Comment

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

iT4iNT SERVER A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email cre...