As cited
Copy frozen at (site build).
Fake Open VSX Extensions Harvest Private Repo and CI Data
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Fake Open VSX Extensions Harvest Private Repo and CI Data
Researchers identified 77 fraudulent extensions in the Open VSX marketplace that communicated with a single command server. Nineteen of these malicious extensions specifically exfiltrated git credentials and continuous integration (CI) identity information from infected development environments.
Why it matters: Developers installing these extensions face credential compromise and unauthorized access to private repositories and CI/CD pipelines, enabling attackers to inject malicious code into software builds or steal sensitive source code.
- Source published
- First seen by Cybersecurity Tracker