Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks

Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks

A critical vulnerability in the Open VSX Registry could allow attackers to take control of the entire extensions marketplace, posing a severe supply chain threat. This flaw puts millions of developer machines at risk by enabling malicious updates to be published through compromised automation workflows. #OpenVSXRegistry #SupplyChainRisk

Keypoints

  • The vulnerability exists in the publish-extensions repository of the Open VSX Registry maintained by the Eclipse Foundation.
  • Attackers can exploit a CI/CD process to publish malicious extensions or updates silently.
  • The flaw stems from the npm install process running arbitrary build scripts with privileged credentials, including a secret token.
  • If compromised, attackers could gain full control over the marketplace and tamper with extensions to insert malicious code.
  • MITRE has added a new β€œIDE Extensions” technique to its ATT&CK framework, highlighting the growing threat of malicious marketplace items.

Read More: https://thehackernews.com/2025/06/critical-open-vsx-registry-flaw-exposes.html