The Hacker News has reported that newly discovered bugs in VSCode Extensions could lead to supply chain attacks. The severe security flaws uncovered in the popular Visual Studio Code extensions could enable attackers to compromise local machines and build/deployment systems through a developer’s integrated development environment (IDE).
The vulnerable extensions can also be exploited to run arbitrary code on a developer’s system remotely, in what could ultimately pave the way for supply chain attacks. Some of the extensions in question are “LaTeX Workshop,” “Rainbow Fart,” “Open in Default Browser,” and “Instant Markdown,” all of which have cumulatively racked up about two million installations between them.