Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks
A serious supply chain risk has been identified by cybersecurity researchers due to a key vulnerability in the Open VSX Registry ("open-vsx[.]org") that, if successfully exploited, might have allowed attackers to take over the whole Visual Studio Code extensions marketplace.
According to researcher Oren Yomtov of Koi Security, this flaw gives attackers complete access over the marketplace for extensions, which in turn gives them complete control over millions of developer computers. A hostile actor could release harmful updates to all Open VSX extensions by taking advantage of a CI flaw.
The maintainers recommended several iterations of changes after responsible disclosure on May 4, 2025, and a final patch was released on June 25.
An open-source project that serves as a substitut...

