# Security notice for Apollo VS Code 11/28/18

DevFeed: [Security notice for Apollo VS Code 11/28/18](<https://devfeed.tech/articles/security-notice-for-apollo-vs-code-11-28-18-23514.md>)

Original publisher: [Read original article](<https://www.apollographql.com/blog/security-notice-for-apollo-vs-code-11-28-18-aafa643765b6>)

Author: James Baxley III

Published: 2018-11-28T22:22:00Z

Content type: news

Language: en

Sources: [Apollo Blog](<https://devfeed.tech/sources/apollo-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [VS Code Extension](<https://devfeed.tech/topics/vscode-extension.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [vs-code](<https://devfeed.tech/topics/vs-code.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [extensions](<https://devfeed.tech/tags/extensions.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Apollo reports that a compromised dependency in the JavaScript ecosystem affected its VS Code extension. The extension was removed from the VS Code Marketplace along with 38 others, then republished after Apollo locked the dependency to a safe version.

## Source excerpt

tldr; - A wide-spread, industry-wide security vulnerability impacted a dependency of a dependency of the Apollo VS Code plugin called . - The editor extension (along with 38 others) was removed from the VS Code Marketplace. These extensions were also uninstalled for users and flagged as "malicious" within VS Code.