TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Malicious VSCode extensions with installs discovered

55 点作者 leeny11 个月前

3 条评论

ralferoo11 个月前
Interesting that there&#x27;s a comment in the article&#x27;s comments that talks about the<p>&gt; client_sock. connect (9090, &quot;192.168.71.132&quot;, () → { ...<p>And then goes on to say that it mostly looks innocent. Except to me, that makes me think that this code is probably aimed at a specific target where they&#x27;ve already hacked one internal box, but there&#x27;s not much interesting they can get from that box directly, but are now using it as a proxy to try to get a command prompt on developers machines where it&#x27;s more likely there will be random passwords and configuration data that could be harvested.<p>It could even feasibly point to someone who&#x27;s already employed by the victim company who knows that plugin is used by developers with more access credentials than they have, and are trying to extract them without anything pointing to them. At some point in the future, they could just add that IP to their box that&#x27;s already in the target network and bingo shells on their victims machines would start appearing.
评论 #40640721 未加载
omoikane11 个月前
See also:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624000">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624000</a> - We Hacked Multi-Billion $ Companies in 30 Minutes with a VSCode Extension<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624855">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40624855</a> - Malicious VSCode extensions with installs discovered
cjk211 个月前
And my colleagues laugh at me for using Apple provided vim with no extensions for everything…
评论 #40640451 未加载