logo

Open VSX rotates access tokens used in supply-chain malware attack

ID: 01db910d-3fe4-5df7-b116-3c8741d98d9e

STIX ID: report--01db910d-3fe4-5df7-b116-3c8741d98d9e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-11-02

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Open VSX access tokens were accidentally leaked by developers and subsequently abused to publish malicious extensions (the GlassWorm campaign) that targeted developer credentials and cryptocurrency wallet data via hidden Unicode payloads; the Eclipse Foundation and Open VSX rotated or revoked tokens and removed malicious extensions, containing the incident, while researchers report the actors have since shifted tactics and moved to GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.