77 Open VSX extensions found harvesting developer info
Summary
A security audit discovered 77 extensions on the Open VSX marketplace that were impersonating legitimate developer tools. These malicious extensions were found to be harvesting information about the systems and development environments where they were installed.
IFF Assessment
FOE
The discovery of malicious extensions designed to harvest developer information poses a direct threat to developers and their organizations.
Defender Context
Developers should exercise extreme caution when installing extensions, even from reputable marketplaces like Open VSX. Regularly auditing installed extensions and scrutinizing their permissions and behaviors is crucial to prevent potential information theft and system compromise.