#OpenVSX
Introducing 🌳tarborist: a VS Code extension providing tree-sitter powered static analysis of {targets} pipelines with target info on hover, tar_map() autocompletion, cycle detection, and upstream/downstream info/links #RStats

Github:
github.com/tylermorganw...

OpenVSX:
open-vsx.org/vscode/item?...
April 3, 2026 at 9:58 PM
The extension name is "Claude Themes by Zhangcy". In the latest Positron release, OpenVSX extensions are served from our Public Package Manager (P3M) p3m.dev/openvsx/late...
Posit Package Manager
p3m.dev
May 9, 2026 at 8:32 PM
VSCでObsidianみたいなことする拡張機能です‼️
つかってね〜🥳✨

Marketplace
marketplace.visualstudio.com/items?itemNa...

OpenVSX
open-vsx.org/extension/ba...

GitHub
github.com/barineco/per...
August 4, 2026 at 3:16 PM
Our IDE extension is now available on OpenVSX, allowing installation on many VSCode-compatible editors like VSCodium, Cursor, and Trae.

👉 open-vsx.org/extension/el...

#gamedev #vndev #naninovel
March 6, 2025 at 7:57 PM
Lots of new features in the "pre-release" channel of our VSCode Extension, on both the VSCode Marketplace and OpenVSX! Take a look and let us know how you get on?
July 8, 2026 at 2:20 AM
A new and ongoing supply-chain attack is targeting developers on the OpenVSX and Microsoft Visual Studio marketplaces with self-spreading malware called GlassWorm that has been installed an estimated 35,800 times.
Self-spreading GlassWorm malware hits OpenVSX, VS Code registries
A new and ongoing supply-chain attack is targeting developers on the OpenVSX and Microsoft Visual Studio marketplaces with self-spreading malware called GlassWorm that has been installed an estimated 35,800 times.
www.bleepingcomputer.com
October 20, 2025 at 4:13 PM
IDE extensions are a silent nightmare.

VS Code extensions get full access to your code and creds, and attackers have already slipped malware into VS Code Marketplace and OpenVSX.

So Socket now scans OpenVSX extensions before they ever hit your machine. 🔍⚡️
November 20, 2025 at 5:39 PM
🚨 We detected malicious OpenVSX releases of Aqua Trivy (1.8.12 & 1.8.13) that injected natural-language prompts to weaponize local AI coding agents.

The releases occurred during a broader AI-powered attack targeting #OSS projects.

Full analysis ↓
socket.dev/blog/unautho...
Unauthorized AI Agent Execution Code Published to OpenVSX in...
OpenVSX releases of Aqua Trivy 1.8.12 and 1.8.13 contained injected natural-language prompts that abuse local AI coding agents for system inspection a...
socket.dev
March 2, 2026 at 8:48 AM
A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems.
New GlassWorm attack targets macOS via compromised OpenVSX extensions
A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems.
www.bleepingcomputer.com
February 2, 2026 at 10:04 PM
FYI for Positron users missing RStudio's Packages pane:
Dianyi Yang created an extension on OpenVSX that replicates the feature!
open-vsx.org/extension/kv...
Open VSX Registry
open-vsx.org
November 14, 2025 at 7:04 PM
🔓 Good news for non–VS Code users: the Unison LSP is now available via OpenVSX!

Give it a try here:

open-vsx.org/extension/un...
Open VSX Registry
open-vsx.org
June 17, 2025 at 6:10 PM
The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now in its third wave, with 24 new packages added on the two platforms.
Glassworm malware returns in third wave of malicious VS Code packages
The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now in its third wave, with 24 new packages added on the two platforms.
www.bleepingcomputer.com
December 1, 2025 at 9:08 PM
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions.
www.bleepingcomputer.com
March 18, 2026 at 3:22 AM
SecureAnnex found a malicious extension on the OpenVSX marketplace for VSCode extensions that was mostly malicious but nobody bothered to check its source.... and 200,000 installed it!

We love web devs!

secureannex.com/blog/these-v...
These Vibes Are Off
Open VSX offers extensions for AI code editors, but at what cost?
secureannex.com
July 2, 2025 at 11:56 PM
The Eclipse Foundation says it contained the GlassWorm that was spreading on OpenVSX.

It also rotated creds for a bunch of developers that leaked their OpenVSX publishing tokens.

blogs.eclipse.org/post/mika%C3...
Open VSX security update, October 2025
Over the past few weeks, the Open VSX team and the Eclipse Foundation have been responding to reports of leaked tokens and related malicious activity involving certain extensions hosted on the Open VS...
blogs.eclipse.org
November 1, 2025 at 11:20 PM
I updated the VS Code/Positron #RStats extension🌳tarborist last night to v0.3.0, which introduces a user setting to declare custom simple target factories (of the form name/command) and have them parsed by the extension.

Install via OpenVSX (right in Positron)

GH:
github.com/tylermorganw...
April 6, 2026 at 4:16 PM
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions.
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions.
www.bleepingcomputer.com
March 17, 2026 at 9:43 PM
openvsx is improving, but also, you're just not interesting enough to get a new editor anyway that's still just vscode with a name switch

zed is the only thing I think is credible, and their problem is also extensions-related (in that they do not have enough of them)
November 18, 2025 at 5:28 PM
🚨 First-ever self-propagating #GlassWorm malware is targeting developers via the #OpenVSX marketplace, hijacking VSCode extensions, stealing credentials and using the #Solana blockchain for control. 🔐

Read: hackread.com/glassworm-ma...

#Cybersecurity #SupplyChainAttack #Malware #VSCode #Malware
GlassWorm Malware Targets Developers Through OpenVSX Marketplace
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
October 23, 2025 at 10:38 AM
I spent a day perusing the last few months of openvsx packages and digging up worms 😅
Glassworm actually seems to be the only active campaign right now on openvsx (or whatever else is going on is hiding it reaaaal good. Though these are 10mb+ packages so who knows right)
The rest are just one offs.
⚠️ UPDATE: we're now tracking 213+ affected package artifacts across this campaign!

socket.dev/supply-chain...
March 18, 2026 at 9:03 AM