Tag: supply-chain malware attack

Open VSX rotates access tokens used in supply-chain malware attack
News

Open VSX rotates access tokens used in supply-chain malware attack

Following an unintentional developer disclosure in public repositories, the Open VSX registry rotated access tokens, enabling threat actors to publish malicious extensions in a supply chain assault. When Wiz researchers announced that more than 550 secrets were exposed throughout the Microsoft VSCode and Open VSX marketplaces two weeks ago, they found the breach. According to reports, some of those secrets might grant access to projects with 150,000 downloads, enabling threat actors to upload malicious extension versions and posing a serious risk to the supply chain. The Eclipse Foundation created Open VSX, an open-source substitute for Microsoft's Visual Studio Marketplace, which provides VSCode IDE extensions. Open VSX is a community-driven registry for extensions compatible...