Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Saturn’s Enceladus moon could harbor life

EU invests €358 million in new LIFE program projects

Massive ClickFix phishing attack using PureRAT malware targets hotel systems

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Eclipse Foundation revokes leaked open VSX tokens following Wiz discovery
Identity

Eclipse Foundation revokes leaked open VSX tokens following Wiz discovery

userBy userOctober 31, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 31, 2025Ravi LakshmananMalware/Secure Coding

Open VSX Token

The Eclipse Foundation, which manages the open source Open VSX project, said it has taken steps to revoke a small number of tokens that were leaked within a Visual Studio Code (VS Code) extension published in the marketplace.

This action follows a report from cloud security firm Wiz earlier this month that found that several extensions in both Microsoft’s VS Code Marketplace and Open VSX inadvertently exposed access tokens in public repositories, potentially allowing malicious parties to seize control and distribute malware, effectively contaminating the extension supply chain.

“Through our investigation, we have determined that a small number of tokens were compromised and may have been used to publish or modify extensions,” Mikaël Barbero, head of security at the Eclipse Foundation, said in a statement. “These exposures were caused by developer error and were not caused by a compromise of the Open VSX infrastructure.”

Open VSX said it has also introduced the token prefix format “ovsxp_” in collaboration with the Microsoft Security Response Center (MSRC) to facilitate scanning of published tokens across public repositories.

CIS build kit

Additionally, registry administrators said they have identified and removed all extensions recently reported by Koi Security as part of a campaign named “GlassWorm,” while stressing that the malware distributed through this campaign is not a “self-replicating worm” in that it first needs to steal developer credentials in order to expand its reach.

“We also believe that the reported download count of 35,800 overstates the actual number of users affected, as it includes inflated downloads generated by bots and visibility tactics used by threat actors,” Barbero added.

Open VSX said it is implementing a number of security changes to strengthen its supply chain, including:

Shorten token expiration times by default to reduce the impact of accidental leaks Facilitate token revocation upon notification Automatically scan extensions for malicious code patterns and embedded secrets upon publication

The new steps to strengthen the ecosystem’s cyber resilience come as the software supplier ecosystem and developers are increasingly targeted by attacks, giving attackers widespread and persistent access to enterprise environments.

“Incidents like this remind us that supply chain security is a shared responsibility, from publishers carefully managing their tokens to registry administrators improving their detection and response capabilities,” Barbero said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCISA warns that VMware zero-day was exploited in active attack by China-linked hackers
Next Article Sellafield radioactive waste cleanup reaches major milestone
user
  • Website

Related Posts

Massive ClickFix phishing attack using PureRAT malware targets hotel systems

November 10, 2025

GlassWorm malware found in three VS Code extensions that were installed thousands of times

November 10, 2025

Microsoft discovers ‘whisper leak’ attack that identifies AI chat topics in encrypted traffic

November 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Saturn’s Enceladus moon could harbor life

EU invests €358 million in new LIFE program projects

Massive ClickFix phishing attack using PureRAT malware targets hotel systems

GlassWorm malware found in three VS Code extensions that were installed thousands of times

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.