Skip to content
Open VSX Registry Faces Security Incident with Leaked Tokens and Malicious Extensions

Open VSX Registry Faces Security Incident with Leaked Tokens and Malicious Extensions

First seen 4 Nov 2025, 11:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Open VSX registry experienced a security incident where access tokens were leaked by developers in public repositories. This exposure allowed threat actors to publish malicious extensions, affecting projects with significant user bases, including those with 150,000 downloads. The leak was identified by Wiz researchers, prompting the registry to rotate the compromised tokens.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track Glassworm and Eclipse Foundation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed