National Cyber Warfare Foundation (NCWF)

Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks


0 user ratings
2025-10-15 15:49:31
milo
Blue Team (CND)
New research has uncovered that publishers of over 100 Visual Studio Code (VS Code) extensions leaked access tokens that could be exploited by bad actors to update the extensions, posing a critical software supply chain risk.
"A leaked VSCode Marketplace or Open VSX PAT [personal access token] allows an attacker to directly distribute a malicious extension update across the entire install base,"



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/10/over-100-vs-code-extensions-exposed.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.