#open-vsx

[ follow ]
Information security
fromThe Hacker News
1 week ago

Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks

A vulnerability in Open VSX allowed malicious VS Code extensions to bypass security checks due to misinterpreted scan results.
Information security
fromThe Hacker News
1 month ago

Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions

The Eclipse Foundation will require pre-publish security checks on Open VSX Registry VS Code extensions to proactively prevent malicious or compromised extensions.
fromThe Hacker News
2 months ago

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm

On January 30, 2026, four established Open VSX extensions published by the oorzc author had malicious versions published to Open VSX that embed the GlassWorm malware loader, These extensions had previously been presented as legitimate developer utilities (some first published more than two years ago) and collectively accumulated over 22,000 Open VSX downloads prior to the malicious releases.
Information security
Information security
fromThe Hacker News
2 months ago

VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX

AI-powered VS Code forks recommend non-existent Open VSX extensions, enabling attackers to register those namespaces and publish malicious packages that compromise developers.
fromThe Hacker News
4 months ago

Malicious VSX Extension "SleepyDuck" Uses Ethereum to Keep Its Command Server Alive

In the latest instance detected by the enterprise extension security firm, the malware is triggered when a new code editor window is opened or a .sol file is selected. Specifically, it's configured to find the fastest Ethereum Remote Procedure Call (RPC) provider to connect to in order to obtain access to the blockchain, initialize contact with a remote server at "sleepyduck[.]xyz" (hence the name) via the contract address " 0xDAfb81732db454DA238e9cFC9A9Fe5fb8e34c465," and kicks off a polling loop that checks for new commands to be executed on the host every 30 seconds.
Information security
[ Load more ]