Bleepingcomputer Open VSX Registry Faces Security Incident with Leaked Tokens and Malicious Extensions
Article Content
Browse articles
The Open VSX registry experienced a security incident where access tokens were leaked by developers in public repositories. This exposure allowed threat actors to publish malicious extensions, affecting projects with significant user bases, including those with 150,000 downloads. The leak was identified by Wiz researchers, prompting the registry to rotate the compromised tokens.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (4)
Following this threat?
Track Glassworm and Eclipse Foundation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PEEP Chrome Extension Turns Browsers Into Remote Access Tools Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be installed, allowing it to bypass Web Store checks and inject itself directly into Chrome and Edge profiles.…
Armored Likho Expands Cyber-Espionage with New Rust Toolkit In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and educational institutions. The attackers employed a fraudulent donation-service application as the initial…