Malicious VSCode extensions with millions of installs discovered

floofloof@lemmy.ca to Programming@programming.dev – 234 points –
Malicious VSCode extensions with millions of installs discovered
bleepingcomputer.com
53

You are viewing a single comment

Microsoft doesn't have a vetting process for publishing extensions in the store. Maybe the failure is that people assume they do?

Surely you mean "that Microsoft does not make it clear that they don't"?

Maybe, but I think the only app store that does vet apps is the Apple one, so that should be the default expectation.

And I think even they wouldn't manually look for something like this. They're mainly concerned about people breaking the commercial rules.