VS Code 1.123 adds a two-hour delay before extensions auto-update to newer versions when automatic updates are enabled.
For more than a year, a self-propagating worm rode VS Code extensions, npm packages, and stolen developer credentials through ...
A new campaign involving malicious Visual Studio Code (VS Code) extensions has exposed a loophole in the VS Code Marketplace that allows threat actors to reuse names of previously removed packages.
The agent is doing the actual work, and VS Code is just a window.
Critical and high-severity vulnerabilities were found in four widely used Visual Studio Code extensions with a combined 128 million downloads, exposing developers to file theft, remote code execution, ...