10 ms·
Hi - Isidor here from the VS Code team. A member of the community did a deep security analysis of the extension and found multiple red flags that indicate mali
by isidorn 2y ago
Hi - Isidor here from the VS Code team.
A member of the community did a deep security analysis of the extension and found multiple red flags that indicate malicious intent and reported this to us.
Our security researchers at Microsoft confirmed this claims and found additional suspicious code.
We banned the publisher from the VS Marketplace and removed all of their extensions and uninstalled from all VS Code instances that have this extension running. For clarity - the removal had nothing to do about copyright/licenses, only about potential malicious intent.
Expect an announcement here with more details soon https://github.com/microsoft/vsmarketplace/ https://github.com/microsoft/vsmarketplace/
As a reminder, the VS Marketplace continuously invests in security. And more about extension runtime trust can be found in this article https://code.visualstudio.com/docs/editor/extension-runtime-security https://code.visualstudio.com/docs/editor/extension-runtime-...
Thank you!
- joshka 2y agoCan you please clarify whether the fork also suffers from the same security issues (or engage the fork's owner to ensure that it doesn't https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you)
- isidorn 2y agoThanks for flagging it. Our security researchers will analize it and based on their findings we might remove this one as well.
- csears 2y agos/analize/analyze/g
- theo-steiner 2y agos/g/
- theobr 2y agoHi, owner of the fork here. I did a thorough combing of the code base when I forked. Just did another audit and still not seeing anything suspicious. Gutting all of the opencollective and changelog code to be 1000% sure.
- theobr 2y agoThe only potential risk was the use of sanity to render a changelog. I didn't want to risk it, so I gutted that and a ton of other stuff. Just published a new, stripped down version. https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you/pull/11 https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you/p...
- f272529 2y agoOk, but did you remove something that explicitly appeared malicious? This is a key detail that I am not seeing in your comments or commit messages.
- jorams 2y agoThat's covered by > I did a thorough combing of the code base when I forked. Just did another audit and still not seeing anything suspicious.
- maxloh 2y agoHi. Please do not replace the original author's copyright notice in the LICENSE file. That is a violation of the Apache License. You could instead "append" your name to the copyright notice though, which is legal. https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you/commit/9e66548c8cca908139e192ab45dbd91cbad6faab https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you/c...
- Der_Einzige 2y ago[flagged]
- ande-mnoc 2y agoWill Microsoft consider adding a permission model for extensions?
- isidorn 2y agoThis is tracked in this feature request https://github.com/microsoft/vscode/issues/52116 https://github.com/microsoft/vscode/issues/52116 We do not plan to add a permission model in the next 6 months.
- fragmede 2y agoGiven the enormity of the attack surface that has just been exposed, that's disappointing.
- Aeolun 2y agoThis isn’t really exposed so much as exploited. This was always possible.
- fragmede 2y agoyou're right. it's not new. https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-with-millions-of-installs-discovered/ https://www.bleepingcomputer.com/news/security/malicious-vsc...
- yukIttEft 2y ago> We do not plan to add a permission model in the next 6 months. I guess Copilot functionality trumps "Security above all else" now. https://blogs.microsoft.com/blog/2024/05/03/prioritizing-security-above-all-else/ https://blogs.microsoft.com/blog/2024/05/03/prioritizing-sec...
- misnome 2y agoYeah, the vscode release notes used to be lists of interesting new things and novel improvements. Now they are all “copilot” “features”.
- WhyNotHugo 2y agoThe issue to which op links now yields 404. What's up with that?
- isidorn 2y agoI am in European time and I do not know what happened on that post (since I was sleeping). I assume it were some heated arguments between maintainer and community about license/copyrights/open source maintenance.
- joshka 2y agohttps://web.archive.org/web/20250226020241/https://github.com/material-theme/vsc-material-theme/discussions/1313 https://web.archive.org/web/20250226020241/https://github.co...
- joshka 2y agohttps://web.archive.org/web/20250226020241/https://github.com/material-theme/vsc-material-theme/discussions/1313 https://web.archive.org/web/20250226020241/https://github.co...
- ytpete 2y agoWeirdly, this Wayback link is now also a 404. I didn't realize content can retroactively get removed from the archive like that – doesn't that sort of defeat one of its main purposes?
- buttercraft 2y agoJust to be clear, which publisher was banned? Maybe I'm being stupid (it's late here) but I'm struggling to track the various parties involved. Anyway, thank you for the update.
- isidorn 2y agoThe publisher Equinusocio was banned.
- anakaine 2y agoYou might need to chase down reuploads, too. https://marketplace.visualstudio.com/items?itemName=t3dotgg.vsc-material-theme-but-i-wont-sue-you https://marketplace.visualstudio.com/items?itemName=t3dotgg....
- isidorn 2y agoThanks. Our security researchers will review this today and we might take it down. We reached out to the new author and he does not have malicious intent, and agreed that we just take down the new extension if we see something is off.
- Lermatroid 2y agoThis is a older pinned version before the license and malware stuff started going down afaik https://youtu.be/3wz7YF2as-c https://youtu.be/3wz7YF2as-c
- rfl890 2y agoMaybe point to the actual reupload instead? https://marketplace.visualstudio.com/items?itemName=fanny.vsc-fanny-theme https://marketplace.visualstudio.com/items?itemName=fanny.vs...
- riquito 2y agoWild how its github page (1 commit, 1 hour ago) has already 885 forks and 11.2K stars to mislead people https://github.com/Fanny-Theme/fanny-theme-support https://github.com/Fanny-Theme/fanny-theme-support
- bagels 2y agoThis is really confusing to me. The original discussion was about changing licenses, but somehow (coincidentally?) there was malicious code discovered shortly after? Are these related?
- dark-star 2y agoIt's a common theme: - build an open-source thing - wait till thousands or millions of people are using it - change the license and close down the source - implement malicious code - push an update - profit! you now have your malware running on millions of systems
- oneeyedpigeon 2y agoThis is a good description of the problem. I'm not sure why it's been downvoted, except that "common" is overstating it a bit.
- notpushkin 2y agoThe closing down step is optional. Just don’t build on a public CI, and inject malicious code in your builds, xz-style.
- pickledoyster 2y agoyup, many mobile app developers do this (inject any SDK that'd pay them) too. Doesn't need to be open source, though
- DANmode 2y agoMobile app devs are often scum, but no need to single them out. Plenty of bait and switch later free apps turned freemium, or malicious, out there.
- jeroenhd 2y agoShould be added that the malicious part is often done by a third party that takes over an open source project when the original developer doesn't have the time/energy/money to maintain their open source/free work. Many Chrome extensions end up being sold for thousands or just hundreds of dollars because there's no money in them and the dev isn't all that interested. Society as a whole could easily avoid this by funding open source/free utilities to the point where malware makers need to spend significant cash to outbid yearly community support, but unfortunately maintaining anything available online for free is a thankless job that barely covers the electricity required to maintain the code. In this case too, the developers behind the theme seemed to want to monetise their work, which had attained almost 4 million installs, in the past, but found themselves with a rather unwilling customer base. I don't know if they snapped and uploaded something malicious or if they're intentionally making it hard for forks to copy their work, but either way the lesson learned is that if you want to make money you should just abandon your free projects and start something else.
- Ayfri 2y ago[flagged]
- BigParm 2y agoImagine the amount of infected packages we use every day. Probably 20 different governments see everything we do.
- cratermoon 2y agowhy worry about governments so much? You know how many different companies see everything you do? Do you trust all of them? https://www.wired.com/story/gravy-location-data-app-leak-rtb/ https://www.wired.com/story/gravy-location-data-app-leak-rtb...
- CamperBob2 2y agoCompanies didn't intentionally murder 100 million of their own customers in the 20th century alone.
- cratermoon 2y agoThey certainly aided and abetted. See IBM.
- CamperBob2 2y agoBut they didn't murder their own customers. Their customer, a government, did the murdering. As long as government claims the right to a monopoly on violence, it is reasonable to hold them to far, far higher standards than anyone else, including corporations. There is only so much damage one company or one cartel can do, but with government, the downside is unbounded. As I suspect we're about to see for ourselves.
- cratermoon 2y agoNah, let go of that monopoly on violence claptrap. Governments can't do things without corporations to build stuff for them. > Their customer, a government, did the murdering. Using stuff the corporation made and profited from. Max Weber died in 1920, get some new economics.
- danhau 2y agoLetting you know that VSCode is unable to uninstall the extension. It prompts me to uninstall, but when I confirm the window refreshes and the extension is still there, triggering the same "is problematic" prompt. This is an infinite loop. Same behavior when trying to uninstall the usual way from the extensions panel. I had to manually delete the extension's folder in %USERPROFILE%\.vscode\extensions and delete the entry from the json (%USERPROFILE%\.vscode\extensions\extensions.json). VSCode 1.97.2, commit e54c774e0add60467559eb0d1e229c6452cf8447
- isidorn 2y agoThank you for letting us know. We are investigating.
- registeredcorn 2y agoAny update on this? I am not directly impacted, but am unsure about others in my company. Assuming that they may be: * Any specifics on the (potential) impact for affected users? * What they should do to get it removed? Edit: There does seem to be a little bit more information available over at Bleeping Computer[1], but the precise nature of what the malware does is unclear at this time other than that it may be some type of "supply chain attack". It would be good to hear more about the specifics. 1: https://www.bleepingcomputer.com/news/security/vscode-extensions-with-9-million-installs-pulled-over-security-risks/ https://www.bleepingcomputer.com/news/security/vscode-extens...
- josekbono 2y agoIt is my understanding that the VSCode team uninstalled this from the marketplace service, as in, it was remotely uninstalled. I just opened my VSCode on an old laptop that had extensions from this actor and everything under his publishing account got removed.
- shdw 2y agoThank you man, I was getting nuts here trying to uninstall this crap but unable.
- filiptronicek 2y ago> Expect an announcement here with more details soon https://github.com/microsoft/vsmarketplace/ https://github.com/microsoft/vsmarketplace/ Hi Isidor, excited for this! At Open VSX, we'd love to take a look and potentially flag the extension as malicious on our side as well. Are you aware of the version range that the malicious code was included in? I'm asking because https://open-vsx.org https://open-vsx.org does not have any version published since the extension went closed-source.
- flutas 2y agoThe extension file is still available to download directly from MS.[0] I downloaded the file, and unzipped it, but on a cursory glance I only see obfuscated code nothing malicious. [0]: !!!WARNING MAY BE MALICIOUS!!! https://marketplace.visualstudio.com/_apis/public/gallery/publishers/Equinusocio/vsextensions/vsc-material-theme/34.7.9/vspackage https://marketplace.visualstudio.com/_apis/public/gallery/pu...
- HelloNurse 2y agoObfuscated code is malicious, even in case it's harmless.
- flutas 2y agoThen never download an Android app, they're obfuscated by default.
- HelloNurse 2y agoObfuscating Javascript is entirely unnecessary: it signals that the author thinks that they have something to hide. At the very least, the author has delusional notions about the greatness of their source code and they worry about piracy, meaning that there is a high probability of stupid bugs and that they would be difficult to notice because of the obfuscation. Of course in this case the default assumption should be that there is something malicious to hide.
- galagladi 2y agoThey are now evading the ban by rebranding the extension to "Fanny Theme": https://marketplace.visualstudio.com/items?itemName=fanny.vsc-fanny-theme https://marketplace.visualstudio.com/items?itemName=fanny.vs...
- preommr 2y agoIs this a troll name? Fanny is a faily well-known slang term[0] [0] https://en.wikipedia.org/wiki/Fanny#In_slang https://en.wikipedia.org/wiki/Fanny#In_slang
- napolux 2y agoonly in UK IIRC
- iamkonstantin 2y agoMore like “only in the US it isn’t” :)
- floucky 2y agoIt was a popular name in France in the 90s ¯\_(ツ)_/¯
- johnisgood 2y agoYeah, Fanni is still used in Hungary.
- somenameforme 2y agoMight be regional but fanny is definitely slang in the US as well, but very quaint/dated, meaning butt. Would generally be used in some sort of context like a grandma telling a kid, 'Get your fanny over here right this second!' It would never be offensive or used with sexual connotation. It's kind of like the equivalent of wiener.
- 2y ago
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- flutas 2y agoSo is there any proof of the malicious code? The extension file is still available to download directly from MS.[0] (Which, why if you pull it from users are you still allowing downloads first of all.) I downloaded the file, and unzipped it. On a cursory glance I see obfuscated code but zero "red flag" level code, has anyone seen the malicious code claimed? [0]: !!!WARNING CLAIMED TO BE MALICIOUS!!! https://marketplace.visualstudio.com/_apis/public/gallery/publishers/Equinusocio/vsextensions/vsc-material-theme/34.7.9/vspackage https://marketplace.visualstudio.com/_apis/public/gallery/pu...
- bitbasher 2y agoI de-obfuscated most of it and didn't see anything malicious. Was there any particular file that was concerning?
- solomatov 2y agoIs it possible for you to add color theme/icon theme/keymap only extensions, without any executable code? I think, it will improve the security situation a bit. I don't see why the mentioned kinds of extensions should have any code.
- vlovich123 2y agoHelp me square this circle: > A member of the community did a deep security analysis of the extension and found multiple red flags that indicate malicious intent and reported this to us. > As a reminder, the VS Marketplace continuously invests in security If you’re relying on the community to alert you to the issues in the marketplace, perhaps you’re not investing enough in auditing popular extensions yourself? I would also suggest that the trust model for VSCode is fundamentally broken - you’re running arbitrary third party code on client machines without any form of sandboxing. This is a level of security you would not deploy into Azure, so why is “run arbitrary 3p code on someone else’s machine” appropriate for VSCode? While I appreciate the work that the VSCode team does and I use it, the lack of any form of sandboxing has always bothered me.
- bogwog 2y agoI was going to point this weird part of their comment too. Reminder that the Open-VSX extension registry exists: https://open-vsx.org https://open-vsx.org Idk if they removed the malicious theme (or if they have it at all), but if MS isn't doing anything beyond just responding to user reports, you might as well switch to an open registry that probably does the same level of security work, and avoid giving them yet another monopoly.
- davely 2y ago> you’re running arbitrary third party code on client machines without any form of sandboxing. This is a level of security you would not deploy into Azure, so why is “run arbitrary 3p code on someone else’s machine” appropriate for VSCode? More and more, I am starting to think I need to run my development environment (for both work and personal projects) in a VM. I am on MacOS, so UTM or Parallels would work pretty well I think. Sadly, I think my work explicitly forbids us from running VMs or accessing our services from them.
- jerpint 2y agoVSCode in cloud would be great, GitHub tried something similar with GitHub.dev , I haven’t tried it in a while but it didn’t feel quite ready at the time, maybe things have changed
- balch 2y agoGiven that it's been automatically removed from all VS Code instance, is there any way to check if it was previously installed? It's concerning that there's now no way to check if a sytem has been compromised by this
- BtM909 2y agoDoesn't it prompt to uninstall?
- shanselman 2y agoFalse positives suck, and it hurts when it happens. The publisher account for Material Theme and Material Theme Icons (Equinusocio) was mistakenly flagged and has now been restored. In the interest of safety, we moved fast and we messed up. We removed these themes because they fired off multiple malware detection indicators inside Microsoft, and our investigation came to the wrong conclusion. We care deeply about the security of the VS Code ecosystem, and acted quickly to protect our users. I understand that the "Equinusocio" extensions author's frustration and intense reaction, and we hear you. It's bad but sometimes things like this happen. We do our best - we're humans, and we hope to move on from this We will clarify our policy on obfuscated code and we will update our scanners and investigation process to reduce the likelihood of another event like this. These extensions are safe and have been restored for the VS Code community to enjoy. LINKS: Material Theme https://marketplace.visualstudio.com/items?itemName=Equinusocio.vsc-material-theme https://marketplace.visualstudio.com/items?itemName=Equinuso... Material Theme Icons https://marketplace.visualstudio.com/items?itemName=Equinusocio.vsc-material-theme-icons https://marketplace.visualstudio.com/items?itemName=Equinuso... Again, we apologize that the author got caught up in the blast radius and we look forward to their future themes and extensions. We've corresponded with him to make these amends and thanked him for his patience. Scott Hanselman and the Visual Studio Code Marketplace Team - @shanselman