HomeSecurityOpen VSX: Addresses Token Leaks and Malicious Extensions

Open VSX: Addresses Token Leaks and Malicious Extensions

The Open VSX Registry and the Eclipse Foundation have completed their investigation into a major security incident involving exposed developer tokens and malicious extensions. The comprehensive response reveals how the platform is strengthening defenses across the VS Code extension ecosystem following the breach.

See also: 12 malicious extensions in VSCode Marketplace steal data

Open VSX

The security incident began when Wiz researchers discovered multiple extension publishing tokens that had been accidentally exposed by developers in public repositories. The investigation confirmed that a limited number of tokens associated with Open VSX accounts had been compromised, creating a direct path for attackers to publish or modify extensions without authorization.

The Open VSX team emphasized that these exposures resulted from developer error and not an infrastructure breach, immediately revoking all affected tokens upon discovery. The exposure highlighted a critical vulnerability in the development workflow where sensitive credentials can easily be leaked into version control systems. Open VSX worked with the Microsoft Security Response Center to introduce a new token prefix format, specifically designed to make it easier and more accurate to scan for exposed tokens in public repositories, allowing developers and security teams to detect compromised credentials faster.

See also: Self-replicating worm detected in Visual Studio Code

Open VSX: Addresses Token Leaks and Malicious Extensions

Security researchers at Koi Security subsequently identified a coordinated malware campaign dubbed “GlassWorm” that exploited the leaked tokens to publish malicious extensions to the platform. While initial reports described this as a self-replicating worm comparable to the ShaiHulud on npm, Open VSX clarified that the malware operated differently. The extensions were designed to steal developer credentials, allowing attackers to extend their reach across the ecosystem, but the malware did not replicate itself or spread across systems.

The campaign resulted in several malicious extensions reaching the market before removal. Open VSX removed all detected malicious extensions immediately upon notification and revoked the associated tokens without delay. However, the reported download statistics require context. The reported number of 35,800 downloads includes inflated counts generated by bot traffic and visibility boosting tactics used by the attackers, likely overestimating the true impact on users. As of October 21, 2025, Open VSX stated that the incident has been fully contained with no indication of an ongoing breach or malicious extensions remaining on the platform.

The response led to specific improvements that strengthen the platform’s security, including implementing shorter default token expiration periods to limit the impact of the leak, simplifying token revocation workflows for faster response times, and deploying automated security scanning on publish to detect malicious code patterns before extensions reach users.

See also: Over 100 VS Code extensions expose developers

Open VSX: Addresses Token Leaks and Malicious Extensions

Open VSX continues to work closely with affected developers, ecosystem partners, and independent researchers to maintain transparency and enhance proactive measures. These improvements demonstrate how security incidents, while disruptive, can lead to meaningful ecosystem strengthening and stronger protections for the broader developer community that relies on open source extension marketplaces.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS