In a a robust Hacker News thread sparked by Jamf Threat Labs research, a VS Code team member defended the editor's Workspace Trust model as the primary safeguard against repo-based malware -- while ...
Those project files you deleted might not actually be deleted.
VS Code's official Snap package on Linux has a bug first reported in 2024 that still hasn't been fixed and is gobbling up ...
Two malicious VS Code extensions have exfiltrated code snippets, API keys, and proprietary algorithms from 1.5 million ...