Supply Chain Risk in VSCode Extension Marketplaces
Wiz dug up 550+ leaked secrets buried in 500+ public VSCode extensionsâincluding 130+ live access tokens forVSCode MarketplaceandOpenVSX. Thatâs a wide-open door to supply chain attacks through auto-updates. Microsoft reacted fast: dumped the breached tokens, rolled outpre-publish secret scanning, a..