SecDevOps.comSecDevOps.com

VSCode IDE forks expose users to "recommended extension" attacks

BleepingComputer(yesterday)Updated yesterday

Popular AI-powered integrated development environment solutions, such as Cursor, Windsurf, Google Antigravity, and Trae, recommend extensions that are non-existent in the OpenVSX registry, allowing...

Popular AI-powered integrated development environment solutions, such as Cursor, Windsurf, Google Antigravity, and Trae, recommend extensions that are non-existent in the OpenVSX registry, allowing threat actors to claim the namespace and upload malicious extensions. [...]

Source: This article was originally published on BleepingComputer

Read full article on source →

Related Articles