Microsoft has removed two popular VS Code plugins, Material Theme – Free and Material Theme Icons – Free, from the Visual Studio Marketplace on the grounds that they contained malicious code. The two plugins in question had reached a total of 9 million downloads. Now, VS Code users are automatically notified that they have been disabled when they try to run these plugins. Here are the details…
Microsoft has detected a security vulnerability in two popular VS Code plugins with 9 million users
First, cybersecurity researchers Amit Assaraf and Itay Kruk noticed an abnormal code structure in the plugins in question and reported it to Microsoft. While themes normally work with static JSON files, these plugins contained highly complex and encrypted JavaScript code called “release-notes.js”. Such code in open source software is generally considered a precursor to malicious activity.

After the analysis, Microsoft removed the plugins in question and suspended the developer’s account. The company is currently investigating the exact threat these plugins pose. The developer of the plugins, Mattia Astorino (equinusocio), stated that the problem was caused by an unupdated Sanity.io dependency and that he did not add any malicious content. However, he criticized Microsoft for removing the plugins without contacting him.
Microsoft announced that more technical details will be shared on the VS Marketplace GitHub repository soon. Users are currently advised to remove suspicious plugins from their projects. So what do you think about this? Do you use these plugins? You can write your opinions in the comments section below…