Meta's Pyrefly sabotages competing Python extensions without telling you

Meta's Pyrefly Python extension silently disables competing language server extensions globally without user consent or notification, and fails to restore them upon uninstall—creating a supply chain trust violation that could damage user trust in extension ecosystems and expose organizations to undisclosed dependency modifications. This behavior represents a significant governance and security concern for IT organizations managing developer tool sprawl, as it demonstrates how trusted tools can covertly modify system configurations without audit trails or user agency. Organizations should immediately assess their use of Pyrefly, establish extension governance policies, and consider this incident when evaluating vendor practices around system modification and transparency.

Hacker News3 min read
Read full article
Meta's Pyrefly sabotages competing Python extensions without telling you
Meta's Pyrefly Python extension silently disables competing language server extensions globally without user consent or notification, and fails to restore them upon uninstall—creating a supply chain trust violation that could damage user trust in extension ecosystems and expose organizations to undisclosed dependency modifications. This behavior represents a significant governance and security concern for IT organizations managing developer tool sprawl, as it demonstrates how trusted tools can covertly modify system configurations without audit trails or user agency. Organizations should immediately assess their use of Pyrefly, establish extension governance policies, and consider this incident when evaluating vendor practices around system modification and transparency.