Open VSX is a organization tracked across 15 threat clusters and 21 intelligence report mentions on ThreatCluster. First observed November 2, 2025; most recent activity May 27, 2026.
Hackers have compromised Docker images and VSCode extensions for the Checkmarx KICS analysis tool, which is used to identify security vulnerabilities in source code. The attack involved a trojanized KICS Docker image…
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
A resurgence of the GlassWorm malware campaign has been identified, targeting the OpenVSX ecosystem with 73 'sleeper' extensions that become malicious after updates. Six of these extensions have already been activated…
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
The KhangNghiem/fast-draft extension on Open VSX was found to contain multiple malicious releases that deploy a remote access trojan (RAT) and an infostealer. Versions 0.10.89, 0.10.105, 0.10.106, and 0.10.112 were…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
Open VSX, the extension marketplace for VS Code forks like Cursor and Windsurf, has addressed a critical vulnerability known as 'Open Sesame' in its pre-publish scanning pipeline. This flaw allowed malicious extensions…
A variant of the GlassWorm malware has been identified, distributed through a compromised Cursor extension on Open VSX. The attack utilizes a sophisticated infection chain and a resilient command-and-control (C2)…
The GlassWorm malware campaign has intensified its operations by utilizing 72 newly identified malicious Open VSX extensions. These extensions exploit transitive dependencies within developer environments, allowing the…