Leaked Tokens in VS Code Extensions Open Supply-Chain Hole
New research found that publishers of more than 100 Visual Studio Code extensions accidentally exposed personal-access tokens (PATs) and other secrets, enabling attackers to push malicious updates and compromise developers.A total of over 550 validated secrets across more than 500 extensions from hundreds of publishers were discovered, involving AI, cloud, database and marketplace credentials. Microsoft responded by revoking the tokens and adding secret-scanning protections, while users are urged to evaluate extensions, disable auto-updates and maintain a controlled extension inventory.
https://thehackernews.com/2025/10/over-100-vs-code-extensions-exposed.html
Comments
Post a Comment