Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Katy Perry’s “Watch It Burn” named favorite new song of the week

Coco Jones in a basil soda dress at the BET Awards 2026

Noah Kahan reacts to poop found in Philadelphia fan seats

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Eclipse Foundation revokes leaked open VSX tokens following Wiz discovery
Celebrities

Eclipse Foundation revokes leaked open VSX tokens following Wiz discovery

By October 31, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 31, 2025Ravi LakshmananMalware/Secure Coding

Open VSX Token

The Eclipse Foundation, which manages the open source Open VSX project, said it has taken steps to revoke a small number of tokens that were leaked within a Visual Studio Code (VS Code) extension published in the marketplace.

This action follows a report from cloud security firm Wiz earlier this month that found that several extensions in both Microsoft’s VS Code Marketplace and Open VSX inadvertently exposed access tokens in public repositories, potentially allowing malicious parties to seize control and distribute malware, effectively contaminating the extension supply chain.

“Through our investigation, we have determined that a small number of tokens were compromised and may have been used to publish or modify extensions,” Mikaël Barbero, head of security at the Eclipse Foundation, said in a statement. “These exposures were caused by developer error and were not caused by a compromise of the Open VSX infrastructure.”

Open VSX said it has also introduced the token prefix format “ovsxp_” in collaboration with the Microsoft Security Response Center (MSRC) to facilitate scanning of published tokens across public repositories.

CIS build kit

Additionally, registry administrators said they have identified and removed all extensions recently reported by Koi Security as part of a campaign named “GlassWorm,” while stressing that the malware distributed through this campaign is not a “self-replicating worm” in that it first needs to steal developer credentials in order to expand its reach.

“We also believe that the reported download count of 35,800 overstates the actual number of users affected, as it includes inflated downloads generated by bots and visibility tactics used by threat actors,” Barbero added.

Open VSX said it is implementing a number of security changes to strengthen its supply chain, including:

Shorten token expiration times by default to reduce the impact of accidental leaks Facilitate token revocation upon notification Automatically scan extensions for malicious code patterns and embedded secrets upon publication

The new steps to strengthen the ecosystem’s cyber resilience come as the software supplier ecosystem and developers are increasingly targeted by attacks, giving attackers widespread and persistent access to enterprise environments.

“Incidents like this remind us that supply chain security is a shared responsibility, from publishers carefully managing their tokens to registry administrators improving their detection and response capabilities,” Barbero said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCISA warns that VMware zero-day was exploited in active attack by China-linked hackers
Next Article Sellafield radioactive waste cleanup reaches major milestone

Related Posts

Coco Jones in a basil soda dress at the BET Awards 2026

June 28, 2026

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Katy Perry’s “Watch It Burn” named favorite new song of the week

Coco Jones in a basil soda dress at the BET Awards 2026

Noah Kahan reacts to poop found in Philadelphia fan seats

Connect apps without AI capabilities

Trending Posts

Katy Perry’s “Watch It Burn” named favorite new song of the week

June 28, 2026

Coco Jones in a basil soda dress at the BET Awards 2026

June 28, 2026

Noah Kahan reacts to poop found in Philadelphia fan seats

June 28, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.