this post was submitted on 01 Mar 2025
22 points (100.0% liked)
VS Code
864 readers
47 users here now
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
If the dependency has been compromised then extensions that use that dependency and ship compromised code are also compromised. Its a transitive property if it ships bad code.
With that in mind Microsoft yoinking the extension from the market place and user devices seems reasonable. But what was the "loop" they mention?
The linked issue comment has the info about it
Well that's not ideal.
Breaking: software with "free" in the name turns out to be malicious
Thank you :)