Five free Marketplace extensions promise private, locally run coding assistance as developers look for alternatives to metered cloud AI.
Malicious Solidity Pro VS Code extensions steal crypto wallets, API keys, SSH keys, and developer tokens, then exfiltrate the ...
Open VSX extensions exposed developer supply-chain risks. Learn how to audit VS Code extensions and reduce credential exposure.
Microsoft has aligned VS Code's existing agent-plugin feature with a vendor-neutral format for portable skills and MCP servers.
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Development environments have evolved into toolkits for directing coding models and coordinating agents. GitHub Copilot, ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Tom Fenton tackles seven free and open-source AI tools bring local chat, coding, voice, design and research capabilities to personal computers and self-hosted environments.
I found the one file that ends the reinstall nightmare for good ...
BSides Las Vegas 2026 spent three days making the case that AI coding tools are supply chain attack targets. ChainDrop, a ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results