VSCode vulnerability allows one-click GitHub token theft
Hacker News·6d·ammar2
A security researcher discovered a bug in VSCode that lets attackers steal GitHub tokens with minimal user interaction. The vulnerability highlights how even trusted development tools can become attack vectors—a sobering reminder for indie developers to scrutinize extensions and keep their editors patched.
Original story
Read the original on Hacker NewsRelated stories

Devtools
Vivix lets you watch JavaScript execute step-by-step in the browserHacker News Show HN·6d·hlude
Devtools
Capstone: Open-source disassembly framework crosses platforms and architecturesHacker News·6d·gregsadetsky

Devtools
Open Repair Data Standard aims to unify how repair shops track fixesHacker News·6d·cassepipe