Open VSX Registry Faces Security Incident with Leaked Tokens and Malicious Extensions

Open VSX Registry Faces Security Incident with Leaked Tokens and Malicious Extensions

First seen 4 Nov 2025, 11:10 UTC BleepingcomputerGbhackersCyberpressCybersecuritynews 83% similarity 27.8

Article Content

Browse articles
ThreatCluster

The Open VSX registry experienced a security incident where access tokens were leaked by developers in public repositories. This exposure allowed threat actors to publish malicious extensions, affecting projects with significant user bases, including those with 150,000 downloads. The leak was identified by Wiz researchers, prompting the registry to rotate the compromised tokens.

ThreatCluster AI

Community

Browse all →