Two-Line Code Injection in Compromised VS Code Extension Triggers Supply Chain Attack

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

Two-Line Code Injection in Compromised VS Code Extension Triggers Supply Chain Attack

Post by Shane1145 »

ReversingLabs (RL) researchers have uncovered a surge in malicious packages targeting cryptocurrency users and developers.

Notably, RL’s Karlo Zanki reported on PyPI packages designed to infiltrate the Solana ecosystem, while Lucija Valentić exposed npm packages that steal crypto funds by injecting code into legitimate local packages.

https://cyberpress.org/two-line-code-in ... extension/
Post Reply