77 Open VSX extensions found harvesting developer info

Summary

A security audit discovered 77 extensions on the Open VSX marketplace that were impersonating legitimate developer tools. These malicious extensions were found to be harvesting information about the systems and development environments where they were installed.

IFF Assessment

FOE

The discovery of malicious extensions designed to harvest developer information poses a direct threat to developers and their organizations.

Defender Context

Developers should exercise extreme caution when installing extensions, even from reputable marketplaces like Open VSX. Regularly auditing installed extensions and scrutinizing their permissions and behaviors is crucial to prevent potential information theft and system compromise.

Read Full Story →