Just in:
Gaslight malware exposes AI triage blind spot // Impossible Marketing Unveils ImpossiblePlus™ AI SEO Solution for Singapore Businesses // SCG Showcases Green Innovations and Low-Carbon Cement at Cemtech Asia 2026, Reinforcing ASEAN Leadership and Commitment to the Net Zero Pathway // Strained Atmosphere Adds To Suspicion About New FCRA Rule Changes // MuddyWater masks espionage behind ransomware playbook // Singapore weighs AI role in boardrooms // Ruggieri links with Novara for Gulf spectacle push // HKSTP Leads Largest-Ever Hong Kong Delegation to BIO 2026 Showcasing Life and Health Tech Strength // EVB Successfully Concludes Power2Drive Europe 2026 With Advanced EV Charging Solutions // ADNOC group secures Bab gas cap concession // Pulsar International (“Pulsar”) announces agreement as an authorized reseller of Amazon Leo to bring high-speed satellite internet to commercial maritime customers // Emirates SkyCargo widens Asian freight reach // Trashure Hunt Opens at Raffles City, Turning Singapore’s Waste Challenge Into Public Art // My Wallet broadens reach beyond TON // EA presses AI into studio workflows // ADNOC Drilling puts AI rig to work early // Dubai summit sets global sports agenda // UAE fines foreign bank branch over compliance lapses // Mannings Continues “Safe Disposal of Unused Medicines Programme” for the Fourth Year Partnering with Community Organisations to Expand Network to 75 Collection Points // GEMS enrolment softens as war delays relocations //

Registry Token Leak Exposes Open VSX Supply-Chain Weakness

A significant security breach involving the open-source extension registry Open VSX Registry and maintained by Eclipse Foundation has exposed a vulnerability in the software-supply-chain ecosystem. Developer tokens that grant publish permissions were unintentionally made public, enabling threat actors to upload malicious extensions and target developers using the platform.

Security researchers from Wiz flagged more than 550 exposed secrets within public repositories, among which tokens belonging to Open VSX accounts were identified. The leaked tokens permitted unauthorised actors to publish or update extensions on the registry, raising alarms about the integrity of code distribution in the developer community.

The Eclipse Foundation’s response confirms that the root cause was human error—developers inadvertently committed tokens to public version-control systems—rather than a breach of Open VSX’s underlying infrastructure. Once identified, the tokens were revoked and all impacted extensions were removed from the registry.

ADVERTISEMENT

One malware campaign tied to this incident has been termed “GlassWorm” by researchers at Koi Security. This operation used the compromised tokens to publish malicious extensions that appear benign at first, then target developer credentials and infrastructure. Despite the name, Open VSX says this campaign did not propagate autonomously like a classic worm, but required credential compromise to expand. Among the affected packages was one disguised as a popular Solidity-language extension, carrying a backdoor invoking Ethereum smart-contract functionality to deliver remote access capabilities.

Download figures circulating in the investigation suggest around 35,800 installs of the suspect extensions, but the registry maintainer cautions that the figure includes inflated counts generated by bots and visibility-manipulation tactics. Because of this, the actual user-impact is likely lower than the headline figure suggests.

In response to the incident, the Eclipse Foundation and Open VSX have enacted a number of security enhancements. Tokens issued for publishing now include a distinct prefix to enable easier detection of exposed credentials in public repositories, implemented in collaboration with Microsoft Security Response Center. Default token lifetimes have been reduced and a streamlined revocation process established to limit the risk exposure window. Automated security scanning of extensions will now run at publication time, enabling earlier detection of malicious code patterns. The registry is also enhancing partnerships with other marketplace operators to share threat intelligence and best practices for extension security.

Beyond the immediate fixes, the incident underscores a broader trend in the software-supply-chain domain: extensions, libraries and plugins represent high-leverage targets for adversaries seeking access to developer environments. Academic work has shown that extension ecosystems can leak credentials, and that a non-trivial share of extensions suffer from data-exposure risks. The decentralised nature of community-driven registries, while enabling innovation, may leave governance and security oversight less robust than enterprise-grade centres.

For development teams and organisations relying on extensions from Open VSX, steps such as verifying publisher authenticity, auditing extension behaviour and integrating secret-scanning tools in CI/CD pipelines are increasingly critical. The incident signals that, even when upstream infrastructure is well maintained, operational practices—especially around token management—remain a primary vector for exploitation.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com