so it turns out that when VS Code asks you “do you trust the authors of this folder?” what they mean is that it’ll auto-execute .vscode/tasks.json if it exists, which can include shell commands.

maybe that’s too many features. you can’t hold all these features. put a few features back

apparently malware gangs have exploited this by offering software engineers “interviews” with a “take-home assignment” so keep that in mind the next time VS Code annoys you with the “do you trust this folder” popup

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/0xabad1dea/statuses/115932064368098942 on your instance and quote it. (Note that quoting is not supported in Mastodon.)