← Back to news

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

The Hacker News08/06/2026, 06:08
Read full article →

Summary

AI-Generated

Key Points:

  • Microsoft has introduced a two-hour delay for automatic updates of extensions in Visual Studio Code to mitigate software supply chain attacks.
  • This delay applies to non-trusted publishers, allowing time for potential malicious updates to be identified before installation, thereby protecting users from compromised releases.
  • Users can still manually update extensions immediately if needed, and similar features have been implemented in other package managers like Bundler, npm, and Yarn.

Technical Details: The new feature is part of VS Code version 1.123 and aims to reduce the risk of installing malicious extensions by introducing a time-based delay before automatic updates occur.

MITRE ATT&CK Techniques: None mentioned

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.