A branded extension campaign aimed at web3 developers shows how a trusted code editor can become the first step in credential and wallet theft.
A malicious extension family tied to Solidity Pro put a familiar developer workflow under suspicion, showing how an editor plugin can become a high-value path to wallets, API keys, and credentials.
Seventy-seven lookalike Open VSX packages show how trusted add-ons can become a low-friction way to collect environment intelligence from developer machines.
A wave of counterfeit VS Code add-ons on Open VSX shows how naming tricks can turn a software marketplace into a developer-risk channel.
Impersonated extensions on a developer marketplace show how a believable namespace can turn software trust into reconnaissance.
Investigators uncover a sprawling network of cloned code extensions poised to unleash GlassWorm malware on unsuspecting developers worldwide.
A subtle software bug let bad actors slip malicious VS Code extensions past Open VSX’s security checks-no hacking required.
The Eclipse Foundation is rolling out pre-publish security scans for Open VSX Registry extensions, targeting the growing threat of supply chain attacks.