Skip to content
The Nexus
DossierENTITY

Open VSX

Coverage of Open VSX in the Nexus archive.

Earliest in view: Apr 10 · 13:23 UTCMost recent: Aug 10 · 07:38 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 10 · 07:38 UTCTHE HACKER NEWS
    Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

    Cybersecurity researchers flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro"). This extension was observed delivering a browser wallet and credential stealer. The specific extensions identified as malicious include helper-beeps.solidity-pro and web3devtoolsx.solidity-pro.

  • SECURITYAug 4 · 18:50 UTCBLEEPING COMPUTER
    77 Open VSX extensions found harvesting developer info

    77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed.

  • SECURITYApr 28 · 14:59 UTCDARK READING
    Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain

    Attackers are distributing malicious VS Code extensions via Open VSX, exploiting supply chain vulnerabilities to spread self-propagating malware. The campaign involves seeding seemingly benign extensions that act as vectors for malware propagation.

  • SECURITYApr 23 · 16:05 UTCBLEEPING COMPUTER
    New Checkmarx supply-chain breach affects KICS analysis tool

    Hackers compromised Docker images, VSCode, and Open VSX extensions for Checkmarx's KICS analysis tool to steal sensitive data from developer environments. The breach exploits the supply chain to harvest information from affected systems.

  • SECURITYApr 10 · 13:23 UTCTHE HACKER NEWS
    GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

    The GlassWorm campaign has evolved with a new Zig dropper designed to infect multiple developer IDEs. Researchers identified the threat in a malicious Open VSX extension named 'specstudio.code-wakatime-activity-tracker,' which disguises itself as the legitimate WakaTime tool.