{"id":828,"date":"2025-07-08T13:01:00","date_gmt":"2025-07-08T13:01:00","guid":{"rendered":"https:\/\/infosec-daily.com\/?page_id=828"},"modified":"2025-07-08T13:01:00","modified_gmt":"2025-07-08T13:01:00","slug":"malicious-pull-request-targets-6000-developers-via-vulnerable-ethcode-vs-code-extension","status":"publish","type":"page","link":"https:\/\/infosec-daily.com\/?page_id=828","title":{"rendered":"Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension"},"content":{"rendered":"<p>Cybersecurity researchers have flagged a supply chain attack targeting a Microsoft Visual Studio Code (VS Code) extension called Ethcode that has been installed a little over 6,000 times.<br \/>\nThe compromise, per ReversingLabs, occurred via a GitHub pull request that was opened by a user named Airez299 on June 17, 2025.<br \/>\nFirst released by 7finney in 2022, Ethcode is a VS Code extension that&#8217;s used to<\/p>","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have flagged a supply chain attack targeting a Microsoft Visual Studio Code (VS Code) extension called Ethcode that has been installed a little over 6,000 times. The compromise,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":829,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"saved_in_kubio":false,"footnotes":""},"class_list":["post-828","page","type-page","status-publish","has-post-thumbnail","hentry"],"kubio_ai_page_context":{"short_desc":"","purpose":"general"},"_links":{"self":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/pages\/828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=828"}],"version-history":[{"count":0,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/pages\/828\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/media\/829"}],"wp:attachment":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}