As cited
Copy frozen at (site build).
vulnerabilities
Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces
Wiz Research identified over 550 secrets exposed in Visual Studio Code (VSCode) extension marketplaces and coordinated with Microsoft to remediate the issue. The exposure represented a significant supply chain vulnerability where sensitive credentials could be discovered and exploited by threat actors.
Why it matters: Developers relying on VSCode extensions face supply chain compromise risk if exposed secrets in the marketplace enable attackers to access infrastructure or inject malicious code into the extension ecosystem.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces
Wiz Research identified over 550 secrets exposed in Visual Studio Code (VSCode) extension marketplaces and coordinated with Microsoft to remediate the issue. The exposure represented a significant supply chain vulnerability where sensitive credentials could be discovered and exploited by threat actors.
Why it matters: Developers relying on VSCode extensions face supply chain compromise risk if exposed secrets in the marketplace enable attackers to access infrastructure or inject malicious code into the extension ecosystem.
- Source published
- First seen by Cybersecurity Tracker