That article is awful…
The original post it’s hacking is better: https://medium.com/@amitassaraf/2-6-exposing-malicious-extensions-shocking-statistics-from-the-vs-code-marketplace-cf88b7a7f38f
Medium’s initial no-account view is awful though:
I always found it weird how people are willing to install obscure extensions just like that. For any program that supports them. This doesn’t surprise me at all.
That being said I’ll go recheck the few I have installed…
I don’t think I realized that the extensions could contain code since most of them are just doing syntax highlighting.
You obviously haven’t seen the platformio extension.
It’s a beast, turns VSCode into an embedded IDE and programmer for loads of different microchipsYeah I’m not using anything like that. Bit irresponsible of MS to not audit this stuff, then. Lots of businesses allowing users to install vs code extensions freely even if they’re otherwise restricted for software installs.
There was also recently something similar with ComfyUI, where an extensions was embedded with a malware.