Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
I tried a Claude Code rival that's local, open source, and completely free - how it went ...
Cybersecurity researchers from Socket’s Threat Research team have identified a developer-compromise supply chain attack ...
A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems.
Powerful tools built for developers, useful for everyone ...
Two malicious VS Code extensions have exfiltrated code snippets, API keys, and proprietary algorithms from 1.5 million ...
In a a robust Hacker News thread sparked by Jamf Threat Labs research, a VS Code team member defended the editor's Workspace ...
GlassWorm malware is expanding to open source platforms, targeting macOS users with infostealers.