tuckner
@tuckner
Followers
2K
Following
10K
Media
646
Statuses
4K
Finding bad software extensions at https://t.co/dhLUjMRP1I
Kansas City, MO
Joined May 2008
Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities
thehackernews.com
AI-created VS Code malware and fake npm packages reveal how attackers exploit open-source trust.
0
2
2
Well written piece on ransomvibing that made it's way into the VS Code marketplace https://t.co/u7dWVJviXs
darkreading.com
A published VS Code extension didn't hide the fact that it encrypts and exfiltrates data and also failed to remove obvious signs it was AI-generated.
0
0
3
Extension marketplaces for browsers, code editors, MCP, and more are all designed for consumers and not businesses. They do not want to remove extensions if they don't have to. The risks an individual accepts are not the same as the risks your company does.
0
2
6
@PatrickAlphaC Please be aware that *all* the market places are filled with malware, just follow @secureannex to see. Make sure you validate what they are _before_ you install!
0
2
5
Powerful new Detections are added to Secure Annex. These are already catching subtle exploits like unicode extension names that evade other filters, manipulated download counts, and combinations of suspicious signatures in code.
0
1
3
GitHub and Google testing VS Marketplace security controls?! Glad to see the test attempts have moved on from actually installing a C2 to instead just popping calc. https://t.co/H8RWmR6Ezc
0
0
2
Another edition of "Guess the right solidity". Two of these will compromise your machine the moment you hit install.
30
28
515
100% chance https://t.co/XNEFHNb3il
1
0
7
Vibe-coded ransomware proof-of-concept ended up on Microsoft’s marketplace https://t.co/mAMDvzVIf2
0
1
1
What are chances a 'fonts.js' file that is actually a MacOS script which has variables like 'removedAsian' and is heavily encoded might just be malicious?
1
1
10
Ridiculously cool that Tines is able to connect to MCP servers now. Understand entirely what any of the browser or code extensions you use might actually be doing with a simple ask. Orchestrate your extension review process or check if "Hello Kitty - You Glow Girl Cute Live
2
2
4