Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names Emmie Evans August 29, 2025

Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names

Cybersecurity researchers have discovered a loophole in the Visual Studio Code Marketplace that allows threat actors to reuse names of previously removed extensions.
Software supply chain security outfit ReversingLabs said it made the discovery after it identified a malicious extension named “ahbanC.shiba” that functioned similarly to two other extensions – ahban.shiba and ahban.cychelloworld –

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top