Threat Actors Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Local Coding Tools
ID: 847239b5-fef8-5c64-bda5-ddbceff7af7d
STIX ID: report--847239b5-fef8-5c64-bda5-ddbceff7af7d
Feed Name: cybersecurityNews.com
A supply-chain compromise of the Aqua Trivy VS Code extension on OpenVSX (versions 1.8.12 and 1.8.13) introduced hidden prompts that caused local AI coding assistants to run with permissive flags to scan for credentials, tokens, and sensitive files and to exfiltrate findings (including pushing REPORT.MD to a repo). Socket.dev and StepSecurity linked the tampering to a broader AI-powered bot campaign and a stolen GitHub personal access token used to push the malicious releases; affected developers should uninstall the extensions, audit activity (look for a posture-report-trivy repo and REPORT.MD), rotate credentials, and inspect AI agent logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
