Leaks in Microsoft VS Code Marketplace Put Supply Chain at Risk
ID: 463e3f65-9f1d-5431-a7d7-ad687eeff189
STIX ID: report--463e3f65-9f1d-5431-a7d7-ad687eeff189
Feed Name: Dark Reading
Threat Score
Wiz researchers discovered hundreds of hardcoded secrets inside VS Code extension packages published to public marketplaces (VS Code Marketplace and Open VSX), including personal access tokens and API keys that could allow attackers to update or poison extensions and perform supply-chain attacks; Microsoft revoked exposed tokens and added secret-scanning controls while Open VSX/Eclipse announced mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
