The Open VSX registry rotated access tokens after they were accidentally leaked by developers in public repositories and allowed threat actors to publish malicious extensions in a supply chain attack. The leak was discovered by Wiz researchers two weeks ago, when they reported an exposure of over 550 secrets across Microsoft VSCode and Open VSX marketplaces. Some of those secrets reportedly could give access to projects with 150,000 downloads, allowing the threat actors to upload malicious versions of extension, creating a significant supply-chain risk. Open VSX, developed under the Eclipse Foundation, is an open-source alternative to Microsoft's Visual Studio Marketplace, a platform that offers extensions for the VSCode IDE. Open VSX serves as a community-driven registry for VS Code–compatible extensions for use on AI-powered forks that cannot use Microsoft's platform, such as Cursor and Windsurf. Some of the leaked tokens were subsequently used in a malware campaign a few days later, dubbed 'GlassWorm'. Koi Security researchers reported that GlassWorm deployed a self-spreading malware hidden within invisible Unicode characters, which attempted to steal developer credentials and trigger cascading breaches across reachable projects. These attacks also targeted cryptocurrency wallet data from 49 extensions, indicating that the attackers' motive was likely financial gain. The Open VSX team and the Eclipse Foundation published a blog post about the campaign and leaked tokens, s...
Open VSX rotates access tokens used in supply-chain malware attack
BleepingComputer
·Bill Toulas
·Published Nov 2, 2025
·Updated
Affected Software
3 affected components
Eclipse Foundation Open VSX
Microsoft Visual Studio Marketplace
Microsoft VSCode
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a supply chain malware attack that exploited leaked access tokens in the Open VSX registry.
2
What security implications are discussed?
The leak of access tokens allowed threat actors to publish malicious extensions, posing a significant risk to users.
3
What products or software are affected?
The affected products include Eclipse Foundation Open VSX, Microsoft Visual Studio Marketplace, and Microsoft VSCode.
4
How did the access tokens become leaked?
The access tokens were accidentally leaked by developers in public repositories.
5
What actions were taken following the discovery of the leak?
The Open VSX registry rotated the compromised access tokens to mitigate the threat.