SlowMist CISO: Alert on Suspicious VSCode Plugins amid Proliferation of Supply Chain Attacks Targeting Developers

Blockbeats
04-21

BlockBeats News, April 21st. SlowMist Chief Security Officer 23pds issued a warning to developers through a retweet of X platform user @mrdotparasyte's post, emphasizing the need for increased vigilance when installing third-party plugins or packages.

Currently, there is a suspicious VSCode plugin named JuanFranBlanco.solidit-vscode, with the term "solidit" in the plugin's Identifier being an obvious spelling mistake. This plugin has been in existence for two to three days, and it is currently unclear how many developers may have inadvertently fallen victim. Supply chain attacks targeting developers are becoming increasingly common, especially in the case of unofficially reviewed VSCode plugins, npm packages, etc., making them prime targets for such attacks.

免責聲明:投資有風險,本文並非投資建議,以上內容不應被視為任何金融產品的購買或出售要約、建議或邀請,作者或其他用戶的任何相關討論、評論或帖子也不應被視為此類內容。本文僅供一般參考,不考慮您的個人投資目標、財務狀況或需求。TTM對信息的準確性和完整性不承擔任何責任或保證,投資者應自行研究並在投資前尋求專業建議。

熱議股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10