benawad / vsinder

Dating App for VSCode
Apache License 2.0
2.47k stars 174 forks source link

Malicious redirect links - please review ASAP #262

Closed ragnarbull closed 1 year ago

ragnarbull commented 1 year ago

The redirect on the ToS and when you try to click "allow" brings up a nasty looking webpage. The domain is getting redirected...probably best to take the ext down until you work out how that's happened. Lots of malicious VS Code extensions recently so I have reported to VS Code.

image
ragnarbull commented 1 year ago

PS. I don't have McAfee so no way am I clicking scan!!!

ragnarbull commented 1 year ago

And when I check my Google account Privacy & Security settings:

image

Not good at all!

Cheos137 commented 1 year ago

it's probably just the domain being bought by someone else... now redirecting everything to a malicious site - so nothing ben or anyone here could change/prevent, thus a takedown from the vscode extension repo (or removing the links from there) is the only thing that seems reasonable

ragnarbull commented 1 year ago

yeah exactly - edited my comment above. I wrote that its probably a domain takeover in the other issue. thanks

voltflake commented 1 year ago

Bens software now acts like a malware, a catchy title for future video 😏 Let's just hope he unpublishes vscode extension as soon as possible...

ragnarbull commented 1 year ago

MSFT just took it down

vs-code-takedown