1.2.3 • Published 4 years ago
@vsliveshare/vscode-launcher-win v1.2.3
Dependency Confusion Attack Distributed via VSCode
This project demonstrates dependency confusion attack via microsoft published vscode extensions.
Quick Start
- start dns server:
yarn dialTone
- mimic installation postinstall script with
yarn phoneHome
(updatenameServers
indigger.ts
to refer to the correct IP address. Remember to rebuild the project for this to work)