Config Files That Run Code: Supply Chain Security Blindspot
signa11
69 points
21 comments
June 08, 2026
Related Discussions
Found 5 related stories in 109.5ms across 10,324 title embeddings via pgvector HNSW
- Supply-chain attack using invisible code hits GitHub and other repositories tannhaeuser · 14 pts · March 15, 2026 · 58% similar
- Supply chain attack alert: .github/setup.js antihero · 20 pts · June 05, 2026 · 53% similar
- Securing the Git push pipeline: Responding to a critical remote code execution samtrack2019 · 14 pts · April 28, 2026 · 50% similar
- An Update on Composer and Packagist Supply Chain Security Seldaek · 21 pts · May 27, 2026 · 49% similar
- No one owes you supply-chain security birdculture · 70 pts · April 12, 2026 · 48% similar
Discussion Highlights (6 comments)
embedding-shape
Is this why Windows Defender is prompting me 2-3 times a day to submit my codex/config.toml to Microsoft for "malware analysis"? I've said no every time so far, since my first thought is "What could even be hidden there?" when I see the dialog yet again, I'm guessing Microsoft would love to see how people use their competitors' products though.
Tangurena2
I've heard about these attacks but never really had the time to understood what was happening. Some of our junior devs use VS Code, so now we have something to point them at.
bpt3
It's far from a blindspot. People have been yelling about this from the rooftops for the last several years. No one cares about security. People used to care for a fairly short period of time after something bad happened to them, but even that seems to have gone by the wayside as breaches, leaks, and use of exploited code has become normalized.
hulitu
> VS Code, Cursor, Claude Code, Gemini CLI, npm, Composer, and Bundler all support config files that can carry a shell command. I think they, and the CIA, call it a feature. Just like messenger apps which try to "execute" every "image file" or link thrown at them.
tuwtuwtuwtuw
Okay, so can I configure VS Code to never run commands in config files?
hadlock
This is MS Word Macros all over again