#openvsx — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #openvsx, aggregated by home.social.
-
77 #OpenVSX extensions found harvesting developer info
-
77 #OpenVSX extensions found harvesting developer info
-
Open VSX 1.0.0 Puts Focus on Open Extension Registry for VS Code Ecosystem
-
Open VSX 1.0.0 Puts Focus on Open Extension Registry for VS Code Ecosystem
-
Thank you, @EclipseFdn, for the free tickets for the @foojay and #BeJUG community for the AI Coding Workshop in Brussels. And congrats to Jonas Helming for the way he presented a massive amount of knowledge, tips, tricks, insights, tools, and much more!
My takeaways and some pictures are in this Foojay blog post:
-
Thank you, @EclipseFdn, for the free tickets for the @foojay and #BeJUG community for the AI Coding Workshop in Brussels. And congrats to Jonas Helming for the way he presented a massive amount of knowledge, tips, tricks, insights, tools, and much more!
My takeaways and some pictures are in this Foojay blog post:
-
RE: https://infosec.exchange/@joshbressers/116754674329757724
Maybe I can try something else besides (neo)vim for real. https://open-vsx.org/ had escaped me even though I've experimented slightly with #Codium.
-
RE: https://infosec.exchange/@joshbressers/116754674329757724
Maybe I can try something else besides (neo)vim for real. https://open-vsx.org/ had escaped me even though I've experimented slightly with #Codium.
-
The #EclipseFdn has launched the Open VSX Security Researcher Recognition Program, creating a clear pathway for responsible vulnerability disclosure in a growing extension ecosystem.
Read the announcement and learn how to participate: https://newsroom.eclipse.org/news/announcements/eclipse-foundation-launches-open-vsx-security-researcher-recognition-program
-
The #EclipseFdn has launched the Open VSX Security Researcher Recognition Program, creating a clear pathway for responsible vulnerability disclosure in a growing extension ecosystem.
Read the announcement and learn how to participate: https://newsroom.eclipse.org/news/announcements/eclipse-foundation-launches-open-vsx-security-researcher-recognition-program
-
WinDev Helper VS Code extension v3.0.0 (more enhancements for the official WinUI dotnet new templates)
https://marketplace.visualstudio.com/items?itemName=alvinashcraft.windev-helper
#windowsdev #winui #vscode #openvsx #windowsappsdk #dotnet #csharp #xaml
-
WinDev Helper VS Code extension v3.0.0 (more enhancements for the official WinUI dotnet new templates)
https://marketplace.visualstudio.com/items?itemName=alvinashcraft.windev-helper
#windowsdev #winui #vscode #openvsx #windowsappsdk #dotnet #csharp #xaml
-
🕵🏻♂️ [InfoSec MASHUP] - This week's news cycle handed us the usual parade of breaches, arrests, and patch-your-stuff urgency — but if you squint at the #Malware section long enough, a more uncomfortable story emerges. #SAP-related npm packages backdoored with a credential stealer. A popular #PyPI package hijacked via a forged signed release pushed through a compromised GitHub Actions workflow. Seventy-three "sleeper" extensions quietly sitting in #OpenVSX, waiting. The common thread: attackers aren't breaking down the front door anymore. They're walking in through the tools developers use every day, often with a valid signature and a clean commit history.
What makes this particularly fun — in the way a slow-motion disaster is fun — is that the blast radius isn't just the developer who ran pip install. It's every downstream user, every CI/CD pipeline, every AI coding agent that helpfully executed the preinstall hook without asking questions. The supply chain isn't a niche threat vector reserved for nation-state ops anymore. It's where commodity attackers are increasingly playing, because it scales beautifully and the detection gap remains embarrassingly wide.
→ Week #18/2026 also covers: Supply chain attackers found the path of least resistance, #OpenSSH patched a bug older than most junior devs, and #Europe is done pretending U.S. #cloud is a neutral choice.
Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one
If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI
-
🕵🏻♂️ [InfoSec MASHUP] - This week's news cycle handed us the usual parade of breaches, arrests, and patch-your-stuff urgency — but if you squint at the #Malware section long enough, a more uncomfortable story emerges. #SAP-related npm packages backdoored with a credential stealer. A popular #PyPI package hijacked via a forged signed release pushed through a compromised GitHub Actions workflow. Seventy-three "sleeper" extensions quietly sitting in #OpenVSX, waiting. The common thread: attackers aren't breaking down the front door anymore. They're walking in through the tools developers use every day, often with a valid signature and a clean commit history.
What makes this particularly fun — in the way a slow-motion disaster is fun — is that the blast radius isn't just the developer who ran pip install. It's every downstream user, every CI/CD pipeline, every AI coding agent that helpfully executed the preinstall hook without asking questions. The supply chain isn't a niche threat vector reserved for nation-state ops anymore. It's where commodity attackers are increasingly playing, because it scales beautifully and the detection gap remains embarrassingly wide.
→ Week #18/2026 also covers: Supply chain attackers found the path of least resistance, #OpenSSH patched a bug older than most junior devs, and #Europe is done pretending U.S. #cloud is a neutral choice.
Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one
If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI
-
GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions
Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.
#GlasswormMalware #Openvsx #MalwareOperations #EmergingThreats #ApplicationSecurity
-
Researchers Expose 73 Fake VS Code Extensions Spreading GlassWorm v2 Malware
Malicious VS Code extensions are putting developers at risk, with 73 fake extensions discovered spreading GlassWorm v2 malware, allowing attackers to stealthily retrieve and execute payloads after activation. These extensions act as loaders, using obfuscated JavaScript to achieve the same malicious…
#MalwareOperations #GlasswormV2 #VsCodeExtensions #OpenVsx #InformationstealingCampaign
-
GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware
La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software. -
GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware
La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software. -
Bugs ohne Bounty: #EclipseFoundation startet Sicherheitsprogramm für #OpenVSX | Developer https://www.heise.de/news/Bugs-ohne-Bounty-Eclipse-Foundation-startet-Sicherheitsprogramm-fuer-Open-VSX-11257225.html @EclipseFdn
-
Bugs ohne Bounty: #EclipseFoundation startet Sicherheitsprogramm für #OpenVSX | Developer https://www.heise.de/news/Bugs-ohne-Bounty-Eclipse-Foundation-startet-Sicherheitsprogramm-fuer-Open-VSX-11257225.html @EclipseFdn
-
The Open VSX Registry continues to grow as shared infrastructure for modern developer platforms.
DevOps.com covers how the Eclipse Foundation is expanding the reach of this vendor-neutral extension marketplace and strengthening its reliability and security.
Read the article:
https://devops.com/eclipse-foundation-extends-scope-and-reach-of-open-vsx-registry/
#OpenSource #DevTools #OpenVSX -
The Open VSX Registry continues to grow as shared infrastructure for modern developer platforms.
DevOps.com covers how the Eclipse Foundation is expanding the reach of this vendor-neutral extension marketplace and strengthening its reliability and security.
Read the article:
https://devops.com/eclipse-foundation-extends-scope-and-reach-of-open-vsx-registry/
#OpenSource #DevTools #OpenVSX -
Glassworm Hides Malware in Invisible Unicode Across 151+ Repos
#GitHub #Cybersecurity #Malware #VSCode #npm #OpenSource #Developers #SoftwareDevelopment #Cybercrime #Hackers #SecurityVulnerabilities #Microsoft #Software #BigTech #VSCodeExtension #GlassWorm #OpenVSX
-
Glassworm Hides Malware in Invisible Unicode Across 151+ Repos
#GitHub #Cybersecurity #Malware #VSCode #npm #OpenSource #Developers #SoftwareDevelopment #Cybercrime #Hackers #SecurityVulnerabilities #Microsoft #Software #BigTech #VSCodeExtension #GlassWorm #OpenVSX
-
Open VSX continues to grow as a trusted infrastructure for modern developer tools.
The Register covers how new industry investment, including support from AWS, is helping strengthen the reliability and sustainability of the vendor-neutral extension registry operated by the Eclipse Foundation.Read the article:
https://www.theregister.com/2026/03/03/open_vsx_aws/ -
Open VSX continues to grow as a trusted infrastructure for modern developer tools.
The Register covers how new industry investment, including support from AWS, is helping strengthen the reliability and sustainability of the vendor-neutral extension registry operated by the Eclipse Foundation.Read the article:
https://www.theregister.com/2026/03/03/open_vsx_aws/ -
📰 Open VSX Marketplace Hit by Supply Chain Attack Spreading "GlassWorm" Malware
📢 Open VSX Registry hit by supply chain attack! A compromised developer account was used to inject GlassWorm malware into 4 popular VS Code extensions, affecting 22k+ downloads. #OpenVSX #SupplyChain #Malware #GlassWorm
-
📰 Open VSX Marketplace Hit by Supply Chain Attack Spreading "GlassWorm" Malware
📢 Open VSX Registry hit by supply chain attack! A compromised developer account was used to inject GlassWorm malware into 4 popular VS Code extensions, affecting 22k+ downloads. #OpenVSX #SupplyChain #Malware #GlassWorm
-
🚨 Open VSX Registry compromised to deploy GlassWorm malware
Four malicious VS Code extensions targeted macOS credentials, VPN sessions, and crypto wallets via a supply-chain attack.
-
🚨 New Research: Threat actors compromised four #OpenVSX extensions, pushed malicious updates that load encrypted malware, evade Russian locales, and fetch C2 instructions via #Solana memos, leading to macOS credential and wallet theft.
Full analysis: https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise
-
🚨 New Research: Threat actors compromised four #OpenVSX extensions, pushed malicious updates that load encrypted malware, evade Russian locales, and fetch C2 instructions via #Solana memos, leading to macOS credential and wallet theft.
Full analysis: https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise
-
AI-Powered Code Editors Could Have Become Malware Delivery Machines: Here's What Happened
https://techlife.blog/posts/vscode-forks-extension-vulnerability/
#VSCode #Cursor #Windsurf #OpenVSX #SupplyChainAttack #ExtensionSecurity #DeveloperTools #Cybersecurity
-
GlassWorm has resurfaced with 24 malicious extensions posing as popular developer tools across Visual Studio Marketplace and Open VSX. The campaign uses Rust implants, Solana-based C2, and inflated download stats to slip harmful updates into trusted environments.
This wave shows how supply-chain attacks continue evolving by blending seamlessly into developer workflows.
What protections do you think dev ecosystems should prioritize next?
Follow us for consistent, unbiased cybersecurity coverage.
#infosec #glassworm #supplychainsecurity #devsecops #vscode #openvsx #malware #threatintel #securityresearch #technadu
-
GlassWorm has resurfaced with 24 malicious extensions posing as popular developer tools across Visual Studio Marketplace and Open VSX. The campaign uses Rust implants, Solana-based C2, and inflated download stats to slip harmful updates into trusted environments.
This wave shows how supply-chain attacks continue evolving by blending seamlessly into developer workflows.
What protections do you think dev ecosystems should prioritize next?
Follow us for consistent, unbiased cybersecurity coverage.
#infosec #glassworm #supplychainsecurity #devsecops #vscode #openvsx #malware #threatintel #securityresearch #technadu
-
#VSCode: 24 malicious VS Code and #OpenVSX extensions are stealing developer credentials - spreading through popular names like Flutter, React, and Tailwind.
Full list of malicious VSCode extensions in the article below:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2025/12/glassworm-returns-with-24-malicious.html -
#VSCode: 24 malicious VS Code and #OpenVSX extensions are stealing developer credentials - spreading through popular names like Flutter, React, and Tailwind.
Full list of malicious VSCode extensions in the article below:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2025/12/glassworm-returns-with-24-malicious.html -
GlassWorm Malware Returns to Open VSX, Emerges on GitHub https://www.securityweek.com/glassworm-malware-returns-to-open-vsx-emerges-on-github/ #ApplicationSecurity #GlassWorm #malware #OpenVSX #VSCode
-
GlassWorm Malware Returns to Open VSX, Emerges on GitHub https://www.securityweek.com/glassworm-malware-returns-to-open-vsx-emerges-on-github/ #ApplicationSecurity #GlassWorm #malware #OpenVSX #VSCode
-
GlassWorm malware returns on OpenVSX with 3 new VSCode extensions https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/
-
GlassWorm malware returns on OpenVSX with 3 new VSCode extensions https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/
-
The #EclipseFdn is excited to announce that Amazon Web Services has made a significant investment to enhance the reliability, performance, and security of critical #opensource infrastructure, including #OpenVSX. Our Executive Director, Mike Milinkovich, shares the details: hubs.la/Q03RQ6Ps0
-
The #EclipseFdn is excited to announce that Amazon Web Services has made a significant investment to enhance the reliability, performance, and security of critical #opensource infrastructure, including #OpenVSX. Our Executive Director, Mike Milinkovich, shares the details: hubs.la/Q03RQ6Ps0
-
‘SleepyDuck’ Malware in Open VSX Lets Attackers Remotely Control Windows PCs https://gbhackers.com/sleepyduck-malware/ #CyberSecurityNews #cybersecurity #Malware #Windows #OpenVSX
-
A trusted Solidity extension turned traitor – the SleepyDuck Trojan used blockchain to stealthily control developers’ tools. Could your favorite extension be hiding a dark secret?
#sleepyduck
#soliditysecurity
#openvsx
#blockchainmalware
#vscodeextension
#cyberthreats
#malwareanalysis
#developersecurity
#infosec -
#OpenVSX: #EclipseFoundation @EclipseFdn zieht Konsequenzen aus #GlassWorm-Attacke | Developer https://www.heise.de/news/Open-VSX-Eclipse-Foundation-zieht-Konsequenzen-aus-GlassWorm-Attacke-10965423.html #VisualStudio
-
Open VSX Downplays Impact From GlassWorm Campaign https://www.securityweek.com/open-vsx-downplays-impact-from-glassworm-campaign/ #Malware&Threats #infostealer #GlassWorm #malware #OpenVSX
-
GlassWorm Malware Targets Developers Through OpenVSX Marketplace https://hackread.com/glassworm-malware-developers-openvsx-marketplace/ #Cybersecurity #VisualStudio #Marketplace #Blockchain #GlassWorm #Security #Malware #OpenVSX #Solana
-
🚨 First-ever self-propagating #GlassWorm malware is targeting developers via the #OpenVSX marketplace, hijacking VSCode extensions, stealing credentials and using the #Solana blockchain for control. 🔐
Read: https://hackread.com/glassworm-malware-developers-openvsx-marketplace/
-
Come on #OpenVSX and #ESF, get your Acts together. We need more pròactive content review. One of the largest Developer ecosystems can’t operate in wild Western Style anymore. https://github.com/eclipse/openvsx/issues/1331#issuecomment-3431458914