home.social

#openvsx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #openvsx, aggregated by home.social.

fetched live
  1. Thank you, @EclipseFdn, for the free tickets for the @foojay and #BeJUG community for the AI Coding Workshop in Brussels. And congrats to Jonas Helming for the way he presented a massive amount of knowledge, tips, tricks, insights, tools, and much more!

    My takeaways and some pictures are in this Foojay blog post:

    foojay.io/today/systematic-ai-

    #Workshop #AI #Theia #OpenVSX EclipseSource

  2. Thank you, @EclipseFdn, for the free tickets for the @foojay and #BeJUG community for the AI Coding Workshop in Brussels. And congrats to Jonas Helming for the way he presented a massive amount of knowledge, tips, tricks, insights, tools, and much more!

    My takeaways and some pictures are in this Foojay blog post:

    foojay.io/today/systematic-ai-

    #Workshop #AI #Theia #OpenVSX EclipseSource

  3. RE: infosec.exchange/@joshbressers

    Maybe I can try something else besides (neo)vim for real. open-vsx.org/ had escaped me even though I've experimented slightly with #Codium.

    #OpenVSX

  4. RE: infosec.exchange/@joshbressers

    Maybe I can try something else besides (neo)vim for real. open-vsx.org/ had escaped me even though I've experimented slightly with #Codium.

    #OpenVSX

  5. The #EclipseFdn has launched the Open VSX Security Researcher Recognition Program, creating a clear pathway for responsible vulnerability disclosure in a growing extension ecosystem.

    Read the announcement and learn how to participate: newsroom.eclipse.org/news/anno

    #OpenVSX #opensource

  6. The #EclipseFdn has launched the Open VSX Security Researcher Recognition Program, creating a clear pathway for responsible vulnerability disclosure in a growing extension ecosystem.

    Read the announcement and learn how to participate: newsroom.eclipse.org/news/anno

    #OpenVSX #opensource

  7. 🕵🏻‍♂️ [InfoSec MASHUP] - This week's news cycle handed us the usual parade of breaches, arrests, and patch-your-stuff urgency — but if you squint at the #Malware section long enough, a more uncomfortable story emerges. #SAP-related npm packages backdoored with a credential stealer. A popular #PyPI package hijacked via a forged signed release pushed through a compromised GitHub Actions workflow. Seventy-three "sleeper" extensions quietly sitting in #OpenVSX, waiting. The common thread: attackers aren't breaking down the front door anymore. They're walking in through the tools developers use every day, often with a valid signature and a clean commit history.

    What makes this particularly fun — in the way a slow-motion disaster is fun — is that the blast radius isn't just the developer who ran pip install. It's every downstream user, every CI/CD pipeline, every AI coding agent that helpfully executed the preinstall hook without asking questions. The supply chain isn't a niche threat vector reserved for nation-state ops anymore. It's where commodity attackers are increasingly playing, because it scales beautifully and the detection gap remains embarrassingly wide.

    → Week #18/2026 also covers: Supply chain attackers found the path of least resistance, #OpenSSH patched a bug older than most junior devs, and #Europe is done pretending U.S. #cloud is a neutral choice.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  8. 🕵🏻‍♂️ [InfoSec MASHUP] - This week's news cycle handed us the usual parade of breaches, arrests, and patch-your-stuff urgency — but if you squint at the #Malware section long enough, a more uncomfortable story emerges. #SAP-related npm packages backdoored with a credential stealer. A popular #PyPI package hijacked via a forged signed release pushed through a compromised GitHub Actions workflow. Seventy-three "sleeper" extensions quietly sitting in #OpenVSX, waiting. The common thread: attackers aren't breaking down the front door anymore. They're walking in through the tools developers use every day, often with a valid signature and a clean commit history.

    What makes this particularly fun — in the way a slow-motion disaster is fun — is that the blast radius isn't just the developer who ran pip install. It's every downstream user, every CI/CD pipeline, every AI coding agent that helpfully executed the preinstall hook without asking questions. The supply chain isn't a niche threat vector reserved for nation-state ops anymore. It's where commodity attackers are increasingly playing, because it scales beautifully and the detection gap remains embarrassingly wide.

    → Week #18/2026 also covers: Supply chain attackers found the path of least resistance, #OpenSSH patched a bug older than most junior devs, and #Europe is done pretending U.S. #cloud is a neutral choice.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  9. GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions

    Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.

    osintsights.com/glassworm-malw

    #GlasswormMalware #Openvsx #MalwareOperations #EmergingThreats #ApplicationSecurity

  10. Researchers Expose 73 Fake VS Code Extensions Spreading GlassWorm v2 Malware

    Malicious VS Code extensions are putting developers at risk, with 73 fake extensions discovered spreading GlassWorm v2 malware, allowing attackers to stealthily retrieve and execute payloads after activation. These extensions act as loaders, using obfuscated JavaScript to achieve the same malicious…

    osintsights.com/researchers-ex

    #MalwareOperations #GlasswormV2 #VsCodeExtensions #OpenVsx #InformationstealingCampaign

  11. GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware

    La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software.

    insicurezzadigitale.com/glassw

  12. GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware

    La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software.

    insicurezzadigitale.com/glassw

  13. The Open VSX Registry continues to grow as shared infrastructure for modern developer platforms.
    DevOps.com covers how the Eclipse Foundation is expanding the reach of this vendor-neutral extension marketplace and strengthening its reliability and security.
    Read the article:
    devops.com/eclipse-foundation-
    #OpenSource #DevTools #OpenVSX

  14. The Open VSX Registry continues to grow as shared infrastructure for modern developer platforms.
    DevOps.com covers how the Eclipse Foundation is expanding the reach of this vendor-neutral extension marketplace and strengthening its reliability and security.
    Read the article:
    devops.com/eclipse-foundation-
    #OpenSource #DevTools #OpenVSX

  15. Open VSX continues to grow as a trusted infrastructure for modern developer tools.
    The Register covers how new industry investment, including support from AWS, is helping strengthen the reliability and sustainability of the vendor-neutral extension registry operated by the Eclipse Foundation.

    Read the article:
    theregister.com/2026/03/03/ope

    #OpenSource #DevTools #OpenVSX

  16. Open VSX continues to grow as a trusted infrastructure for modern developer tools.
    The Register covers how new industry investment, including support from AWS, is helping strengthen the reliability and sustainability of the vendor-neutral extension registry operated by the Eclipse Foundation.

    Read the article:
    theregister.com/2026/03/03/ope

    #OpenSource #DevTools #OpenVSX

  17. 📰 Open VSX Marketplace Hit by Supply Chain Attack Spreading "GlassWorm" Malware

    📢 Open VSX Registry hit by supply chain attack! A compromised developer account was used to inject GlassWorm malware into 4 popular VS Code extensions, affecting 22k+ downloads. #OpenVSX #SupplyChain #Malware #GlassWorm

    🔗 cyber.netsecops.io/articles/op

  18. 📰 Open VSX Marketplace Hit by Supply Chain Attack Spreading "GlassWorm" Malware

    📢 Open VSX Registry hit by supply chain attack! A compromised developer account was used to inject GlassWorm malware into 4 popular VS Code extensions, affecting 22k+ downloads. #OpenVSX #SupplyChain #Malware #GlassWorm

    🔗 cyber.netsecops.io/articles/op

  19. 🚨 Open VSX Registry compromised to deploy GlassWorm malware

    Four malicious VS Code extensions targeted macOS credentials, VPN sessions, and crypto wallets via a supply-chain attack.

    technadu.com/open-vsx-registry

    #InfoSec #SupplyChainSecurity #Malware #OpenVSX #DevSecOps

  20. 🚨 New Research: Threat actors compromised four extensions, pushed malicious updates that load encrypted malware, evade Russian locales, and fetch C2 instructions via memos, leading to macOS credential and wallet theft.

    Full analysis: socket.dev/blog/glassworm-load

  21. 🚨 New Research: Threat actors compromised four #OpenVSX extensions, pushed malicious updates that load encrypted malware, evade Russian locales, and fetch C2 instructions via #Solana memos, leading to macOS credential and wallet theft.

    Full analysis: socket.dev/blog/glassworm-load

  22. GlassWorm has resurfaced with 24 malicious extensions posing as popular developer tools across Visual Studio Marketplace and Open VSX. The campaign uses Rust implants, Solana-based C2, and inflated download stats to slip harmful updates into trusted environments.

    This wave shows how supply-chain attacks continue evolving by blending seamlessly into developer workflows.

    What protections do you think dev ecosystems should prioritize next?

    Follow us for consistent, unbiased cybersecurity coverage.

    #infosec #glassworm #supplychainsecurity #devsecops #vscode #openvsx #malware #threatintel #securityresearch #technadu

  23. GlassWorm has resurfaced with 24 malicious extensions posing as popular developer tools across Visual Studio Marketplace and Open VSX. The campaign uses Rust implants, Solana-based C2, and inflated download stats to slip harmful updates into trusted environments.

    This wave shows how supply-chain attacks continue evolving by blending seamlessly into developer workflows.

    What protections do you think dev ecosystems should prioritize next?

    Follow us for consistent, unbiased cybersecurity coverage.

    #infosec #glassworm #supplychainsecurity #devsecops #vscode #openvsx #malware #threatintel #securityresearch #technadu

  24. #VSCode: 24 malicious VS Code and #OpenVSX extensions are stealing developer credentials - spreading through popular names like Flutter, React, and Tailwind.

    Full list of malicious VSCode extensions in the article below:
    #SoftwareSupplyChainSecurity
    👇
    thehackernews.com/2025/12/glas

  25. #VSCode: 24 malicious VS Code and #OpenVSX extensions are stealing developer credentials - spreading through popular names like Flutter, React, and Tailwind.

    Full list of malicious VSCode extensions in the article below:
    #SoftwareSupplyChainSecurity
    👇
    thehackernews.com/2025/12/glas

  26. The #EclipseFdn is excited to announce that Amazon Web Services has made a significant investment to enhance the reliability, performance, and security of critical #opensource infrastructure, including #OpenVSX. Our Executive Director, Mike Milinkovich, shares the details: hubs.la/Q03RQ6Ps0

  27. The #EclipseFdn is excited to announce that Amazon Web Services has made a significant investment to enhance the reliability, performance, and security of critical #opensource infrastructure, including #OpenVSX. Our Executive Director, Mike Milinkovich, shares the details: hubs.la/Q03RQ6Ps0

  28. 🚨 First-ever self-propagating #GlassWorm malware is targeting developers via the #OpenVSX marketplace, hijacking VSCode extensions, stealing credentials and using the #Solana blockchain for control. 🔐

    Read: hackread.com/glassworm-malware

    #Cybersecurity #SupplyChainAttack #Malware #VSCode #Malware

  29. Come on #OpenVSX and #ESF, get your Acts together. We need more pròactive content review. One of the largest Developer ecosystems can’t operate in wild Western Style anymore. github.com/eclipse/openvsx/iss