logo

Threat Actors Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Local Coding Tools

ID: 847239b5-fef8-5c64-bda5-ddbceff7af7d

STIX ID: report--847239b5-fef8-5c64-bda5-ddbceff7af7d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A supply-chain compromise of the Aqua Trivy VS Code extension on OpenVSX (versions 1.8.12 and 1.8.13) introduced hidden prompts that caused local AI coding assistants to run with permissive flags to scan for credentials, tokens, and sensitive files and to exfiltrate findings (including pushing REPORT.MD to a repo). Socket.dev and StepSecurity linked the tampering to a broader AI-powered bot campaign and a stolen GitHub personal access token used to push the malicious releases; affected developers should uninstall the extensions, audit activity (look for a posture-report-trivy repo and REPORT.MD), rotate credentials, and inspect AI agent logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.