Bleepingcomputer
Open VSX Registry Faces Security Incident with Leaked Tokens and Malicious Extensions
First seen 4 Nov 2025, 11:10 UTC
•


•83% similarity
•27.8
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Open VSX registry experienced a security incident where access tokens were leaked by developers in public repositories. This exposure allowed threat actors to publish malicious extensions, affecting projects with significant user bases, including those with 150,000 downloads. The leak was identified by Wiz researchers, prompting the registry to rotate the compromised tokens.
ThreatCluster AI