• News/
  • https://www.bleepingcomputer.com/news/security/open-vsx-rotates-tokens-used-in-supply-chain-malware-attack/

Open VSX rotates access tokens used in supply-chain malware attack

BleepingComputer
·
Bill Toulas
·
Published Nov 2, 2025
·
Updated

The Open VSX registry rotated access tokens after they were accidentally leaked by developers in public repositories and allowed threat actors to publish malicious extensions in a supply chain attack. The leak was discovered by Wiz researchers two weeks ago, when they reported an exposure of over 550 secrets across Microsoft VSCode and Open VSX marketplaces. Some of those secrets reportedly could give access to projects with 150,000 downloads, allowing the threat actors to upload malicious versions of extension, creating a significant supply-chain risk. Open VSX, developed under the Eclipse Foundation, is an open-source alternative to Microsoft's Visual Studio Marketplace, a platform that offers extensions for the VSCode IDE. Open VSX serves as a community-driven registry for VS Code–compatible extensions for use on AI-powered forks that cannot use Microsoft's platform, such as Cursor and Windsurf. Some of the leaked tokens were subsequently used in a malware campaign a few days later, dubbed 'GlassWorm'. Koi Security researchers reported that GlassWorm deployed a self-spreading malware hidden within invisible Unicode characters, which attempted to steal developer credentials and trigger cascading breaches across reachable projects. These attacks also targeted cryptocurrency wallet data from 49 extensions, indicating that the attackers' motive was likely financial gain. The Open VSX team and the Eclipse Foundation published a blog post about the campaign and leaked tokens, s...

Read full article

Affected Software

3 affected components
Eclipse Foundation Open VSX
Microsoft Visual Studio Marketplace
Microsoft VSCode
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a supply chain malware attack that exploited leaked access tokens in the Open VSX registry.

2

What security implications are discussed?

The leak of access tokens allowed threat actors to publish malicious extensions, posing a significant risk to users.

3

What products or software are affected?

The affected products include Eclipse Foundation Open VSX, Microsoft Visual Studio Marketplace, and Microsoft VSCode.

4

How did the access tokens become leaked?

The access tokens were accidentally leaked by developers in public repositories.

5

What actions were taken following the discovery of the leak?

The Open VSX registry rotated the compromised access tokens to mitigate the threat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203