• @[email protected]
    link
    fedilink
    English
    1424 days ago

    “A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to “infect” over 100 organizations by trojanizing a copy of the popular 'Dracula Official theme to include risky code. Further research into the VSCode Marketplace found thousands of extensions with millions of installs.”

    • @towerful
      link
      English
      224 days ago

      The plugin is called “Darcula Official” btw.

      There is a more generic theme (for multiple applications) called Dracula.
      JetBrains IDE has a theme called Darcula, and there are vscode themes on the marketplace that implement this.

      So, it’s more than just a typosquat