TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Malicious VSCode extensions with installs discovered

55 pointsby leeny11 months ago

3 comments

ralferoo11 months ago
Interesting that there&#x27;s a comment in the article&#x27;s comments that talks about the<p>&gt; client_sock. connect (9090, &quot;192.168.71.132&quot;, () → { ...<p>And then goes on to say that it mostly looks innocent. Except to me, that makes me think that this code is probably aimed at a specific target where they&#x27;ve already hacked one internal box, but there&#x27;s not much interesting they can get from that box directly, but are now using it as a proxy to try to get a command prompt on developers machines where it&#x27;s more likely there will be random passwords and configuration data that could be harvested.<p>It could even feasibly point to someone who&#x27;s already employed by the victim company who knows that plugin is used by developers with more access credentials than they have, and are trying to extract them without anything pointing to them. At some point in the future, they could just add that IP to their box that&#x27;s already in the target network and bingo shells on their victims machines would start appearing.
评论 #40640721 未加载
omoikane11 months ago
See also:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624000">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624000</a> - We Hacked Multi-Billion $ Companies in 30 Minutes with a VSCode Extension<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624855">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624855</a> - Malicious VSCode extensions with installs discovered
cjk211 months ago
And my colleagues laugh at me for using Apple provided vim with no extensions for everything…
评论 #40640451 未加载