SlowMist CISO: Beware of suspicious VSCode plugin "JuanFranBlanco.solidit-vscode"

avatar
PANews
04-21
This article is machine translated
Show original

PANews reported on April 21 that according to 23pds, the chief information security officer of Slow Fog Technology, a post by X platform user @mrdotparasyte revealed a suspicious VSCode plugin named JuanFranBlanco.solidit-vscode. The plugin's download volume appears to have been artificially inflated, and its information is questionable, with the word "solidit" in the plugin Identifier being an obvious spelling error. The plugin has existed for two to three days, and it is currently unclear how many developers have inadvertently been affected. Currently, supply chain attacks targeting developers are becoming increasingly prevalent, with unofficial VSCode plugins and npm packages becoming major attack vectors. Developers are reminded to be vigilant and carefully scrutinize third-party plugins or packages before installation.

Source
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments