As cited
Copy frozen at (site build).
threat intel
77 Open VSX extensions found harvesting developer info
Security researchers identified 77 malicious extensions on the Open VSX marketplace that posed as legitimate developer tools and collected system and development environment information from installations. The extensions harvested data about the systems and development environments where they were installed. These extensions were discovered and removed from the marketplace.
Why it matters: Developers using Open VSX are at risk of installing trojanized tools that exfiltrate sensitive environment and system data; practitioners should audit installed extensions and verify tool legitimacy.
- Source published
- First seen by Cybersecurity Tracker