77 Open VSX extensions found harvesting developer info
According to BleepingComputer, 77 extensions on the Open VSX marketplace were discovered impersonating legitimate developer tools. These malicious extensions were designed to harvest information about the systems and development environments where they were installed. The report indicates that the extensions transmitted this information, potentially exposing sensitive details about developers' setups. The Open VSX marketplace is a community-driven alternative to the Visual Studio Code Marketplace, and this discovery highlights a security concern for developers who rely on such extensions. The article does not specify the names of the affected extensions or the exact type of information harvested, but it underscores the risk of installing extensions from third-party marketplaces without proper verification.
Developers using Open VSX extensions may have unknowingly exposed system and environment information to malicious actors.