A critical vulnerability in the Open VSX Registry could allow attackers to take control of the entire extensions marketplace, posing a severe supply chain threat. This flaw puts millions of developer machines at risk by enabling malicious updates to be published through compromised automation workflows. #OpenVSXRegistry #SupplyChainRisk
Keypoints
- The vulnerability exists in the publish-extensions repository of the Open VSX Registry maintained by the Eclipse Foundation.
- Attackers can exploit a CI/CD process to publish malicious extensions or updates silently.
- The flaw stems from the npm install process running arbitrary build scripts with privileged credentials, including a secret token.
- If compromised, attackers could gain full control over the marketplace and tamper with extensions to insert malicious code.
- MITRE has added a new βIDE Extensionsβ technique to its ATT&CK framework, highlighting the growing threat of malicious marketplace items.
Read More: https://thehackernews.com/2025/06/critical-open-vsx-registry-flaw-exposes.html