VSCode extensions with 9 million installs pulled over security risks (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 27 Feb 2025 12:51
https://sh.itjust.works/post/33512154

#cybersecurity

threaded - newest

will_a113@lemmy.ml on 27 Feb 2025 13:09 next collapse

Mattia Astorino’s ‘Material Theme – Free’ and  'Material Theme Icons – Free‘ plugins for anyone curious.

Harvey656@lemmy.world on 27 Feb 2025 13:23 collapse

Of course it’s material theme stuff. Smh.

lexiw@lemmy.world on 27 Feb 2025 13:50 next collapse

The guy is an absolute twat, don’t believe a word he says.

m.youtube.com/watch?v=3wz7YF2as-c&pp=ygUQVGhlbyBn…

merthyr1831@lemmy.ml on 27 Feb 2025 15:30 collapse

Lmao, Microsoft clearly says themes arent allowed to use scripts and the first thing this jackass does is admit to use obfuscated scripts in his theme. What a dick.

sugar_in_your_tea@sh.itjust.works on 27 Feb 2025 17:05 collapse

That sounds incredibly easy to enforce, why didn’t they?

Vendetta9076@sh.itjust.works on 28 Feb 2025 05:38 next collapse

Because Microsoft hates you

merthyr1831@lemmy.ml on 28 Feb 2025 12:50 collapse

Because people will do the work for them, so why enforce their TOS when they can just say YMMV and have absolutely zero liability if someone’s extension sells your corporate code to the dark web

sugar_in_your_tea@sh.itjust.works on 28 Feb 2025 12:52 collapse

You can still have zero liability with a simple automated check. A theme is just JSON, so if it’s in the theme category, run it through a JSON parser.

That would take a bad developer a day to do.