logo

Cyberattackers Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Coding Tools

ID: 9db430a1-91dd-5181-aa40-41b1997c6dff

STIX ID: report--9db430a1-91dd-5181-aa40-41b1997c6dff

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Aqua Trivy's VS Code extension on OpenVSX was compromised when attackers published malicious versions 1.8.12 and 1.8.13 that injected prompts to launch local AI CLIs (Claude, Codex, Gemini, Copilot, Kiro) in permissive modes to perform system reconnaissance and exfiltrate credentials and sensitive data (including via GitHub CLI). Socket Security alerted Aqua and OpenVSX; the malicious builds were removed and the publishing token revoked within hours, but users are advised to uninstall affected versions, audit histories, scan for rogue repos and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.