VSCODE extensions have removed security risks, but millions of users have already installed


  • Security researchers have found malicious code hiding in two VSCODE extensions
  • Microsoft quickly pulled them and informs users
  • The developer criticized Microsoft’s decision, saying that they had never been consulted

Microsoft has drawn two popular VSCODE extensions from its market after finding malware hiding inside. However, the original developers do not seem to be the culprits and criticized Microsoft for his hard reaction which, according to them, caused more harm than good.

Two security researchers – AMIT ASSARAF and ITAY KRUK – used a specialized scanner to analyze extensions on Visual Studio Marketplace, and found obscured malicious code in “Material theme – Free” and “Material theme icons”, two extensions built by a Mattia Astorino (AKA Equinusocio).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top