#OpenVSX
CVE-2025-12999 - eclipse open vsx
The OpenVSX server builds full web addresses for downloads and other resources using information supplied in certain network headers, without checking whether that…

Too many irrelevant or confusing CVEs? Use stackflag.com

#eclipsefoundation #CVE #infosec
CVE-2025-12999: Eclipse OpenVSX may serve malicious links from forged headers
The OpenVSX server builds full web addresses for downloads and other resources using information supplied in certain network headers, without checking.
stackflag.com
September 21, 2026 at 9:50 AM
“PyPI、Maven Central、crates.io、RubyGems、npm、NuGet、OpenVSX、Packagistなど” のレジストリがAIの影響で維持困難になってるので資金調達に参加してくださいという。うーんたいへんだな……

Sustainable Package Registries: An Enterprise Commitment
Sustainable Package Registries: An Enterprise Commitment
Discover how OpenSSF and major tech enterprises are committing to sustainable funding for public package registries to secure the global software supply chain.
openssf.org
September 17, 2026 at 1:58 AM
For VSCode , cf more info here

* #OpenVSX : open-vsx.org/extension/ro...
* #VisualStudioCode Marketplace: visualstudoomarketplace: marketplace.visualstudio.com/items?itemNa...

For #Thonny :https://gitlab.com/rod2ik/thonny-pseudocode-i18n
Open VSX Registry
open-vsx.org
September 15, 2026 at 8:36 PM
The MIT repo and the build you install are not the same product. Marketplace terms only allow Microsoft's own clients, and the branded build carries the closed bits, so the open source part never covered extension distribution. VSCodium plus OpenVSX is where the rest ended up.
September 3, 2026 at 8:27 AM
In-app terminal performance overhaul
- Remote server upgrades are 5x faster and 100x more reliably
- Remote projects can now be opened in VS Code via ssh with 1 click
- OpenVSX support for custom themes! (3/6)
August 26, 2026 at 4:05 AM
OpenVSX support for custom themes! Use your favorite VS Code themes directly
- Codex skill discovery is way more reliable
- OpenCode skills actually appear in app now
- Claude can discover project-level skills now
- Fixed really annoying auto scroll behaviors and edge cases
-
August 26, 2026 at 3:47 AM
📢 77 extensions Open VSX malveillantes exfiltrent des données git et CI vers un domaine frauduleux

Cet article de recherche documente la découverte de 77 extensions Open VSX contrefaites identifiées entre le 26 juillet et le 1er août…

🟢 vérification factuelle haute
#OpenVSX #CICD #Cyberveille
77 extensions Open VSX malveillantes exfiltrent des données git et CI vers un domaine frauduleux
Cet article de recherche documente la découverte de 77 extensions Open VSX contrefaites identifiées entre le 26 juillet et le 1er août 2026, toutes communicant avec le même domaine nouvellement enregistré mangorbit.com.
cyberveille.ch
August 8, 2026 at 6:00 PM
77 fake Open VSX extensions found exfiltrating developer data. Verify your tools to stay secure. #CyberSecurity #OpenVSX #Malware #SupplyChainAttack #DeveloperTools #DataBreach thedailytechfeed.com/77-malicious...
August 5, 2026 at 3:14 PM
Open VSX removed 77 malicious extensions mimicking legitimate tools, highlighting software supply chain risks. #OpenVSX #SoftwareSupplyChain #Cybersecurity #DeveloperTools #Malware thedailytechfeed.com/open-vsx-rem...
August 5, 2026 at 9:42 AM
77 fake Open VSX extensions mimicked trusted dev tools and exfiltrated system and workspace data. Manifold Security found 19 also harvesting Git and CI metadata in an evil twin campaign. #OpenVSX #Manifold #DevTools
77 Open VSX extensions found harvesting developer info
77 Open VSX extensions impersonated legitimate developer tools in an “evil twin” campaign and sent system and development-environment data to attacker infrastructure. Manifold Security linked the packages to mangorbit[.]com and found that 19 of them collected unusually detailed reconnaissance, including Git and CI metadata. #OpenVSX #ManifoldSecurity #mangorbit
www.hendryadrian.com
August 4, 2026 at 10:45 PM
VSCでObsidianみたいなことする拡張機能です‼️
つかってね〜🥳✨

Marketplace
marketplace.visualstudio.com/items?itemNa...

OpenVSX
open-vsx.org/extension/ba...

GitHub
github.com/barineco/per...
August 4, 2026 at 3:16 PM
Up until a year ago I was consistently getting told that working on the #RadicleVsCode was a waste of time and nobody cares.

Today, the OpenVSX downloads alone crossed the 2,000 mark. In less than two months, 1,000 more of you proved you care.

Thank you. The biggest release yet arrives soon.
July 29, 2026 at 8:04 PM
Turns out we don't have VS Code users, we have fork users. Microsoft's marketplace: 57 installs of our AIVory extension. Open VSX, where Cursor and VSCodium pull from: 2,759. Same build.
https://open-vsx.org/extension/aivory/aivory?utm_source=bluesky&utm_medium=social&utm_campaign=openvsx-forks
July 28, 2026 at 7:16 AM
BTW I am also wrestling with Gradle github.com/eclipse-open... but I don't give up: github.com/cstamas/open... (the "no XML" solution). Just compare that POM to 3 different files in 3 different formats (groovy, toml, whatever)...
GitHub - eclipse-openvsx/openvsx: An open-source registry for VS Code extensions
An open-source registry for VS Code extensions. Contribute to eclipse-openvsx/openvsx development by creating an account on GitHub.
github.com
July 14, 2026 at 5:45 PM
Lots of new features in the "pre-release" channel of our VSCode Extension, on both the VSCode Marketplace and OpenVSX! Take a look and let us know how you get on?
July 8, 2026 at 2:20 AM
made an extension, got mad at m$, some other things
An L5 OpenVSX Extension
Help test the beta!
blog.smarmy.space
July 6, 2026 at 9:56 PM
Vulnerability found in OpenVSX registry, allowing code execution on devs' machines via VS Code-derived editors #vulnerability #security

https://wesearch.press/s/when-your-ide-becomes-a-rce-endpoint-79055c54?utm_source=social&utm_medium=auto&utm_campaign=bluesky
June 30, 2026 at 7:40 PM
Open VSX 1.0.0 Puts Focus on Open Extension Registry for VS Code Ecosystem

buff.ly/NztFYmv

#openvsx #vscode #cursor #extensions #devtools
Open VSX 1.0.0 Puts Focus on Open Extension Registry for VS Code Ecosystem -- Visual Studio Magazine
Eclipse Open VSX has reached 1.0.0, highlighting its role as a vendor-neutral registry for VS Code-compatible extensions.
buff.ly
June 25, 2026 at 8:00 PM
I attended an AI coding workshop organised by the Eclipse Foundation and #openvsx. The training was pragmatic where it showed many tips and pitfalls. I learned a lot things!
June 24, 2026 at 9:20 AM
GlassWorm’s Silent Invasion: The Invisible Malware That Turned Trusted Developer Tools Into a Global Cybersecurity Nightmare + Video

Introduction: When Trust Becomes the Weakest Link For decades, developers have relied on extensions and plugins to accelerate productivity, automate workflows, and…
GlassWorm’s Silent Invasion: The Invisible Malware That Turned Trusted Developer Tools Into a Global Cybersecurity Nightmare + Video
Introduction: When Trust Becomes the Weakest Link For decades, developers have relied on extensions and plugins to accelerate productivity, automate workflows, and simplify software development. These tools have become an inseparable part of modern coding environments, especially within Visual Studio Code and OpenVSX ecosystems. But what happens when the very tools designed to help developers become weapons against them? The emergence of GlassWorm has revealed a chilling reality.
undercodenews.com
June 22, 2026 at 8:20 AM
GlassWorm Self-Propagating Worm Targets Developers Through VS Code and OpenVSX Extensions A highly sophisticated, self-propagating malware known as GlassWorm has been actively targeting developers ...

#Cyber #security #news #vulnerability #Cyber #Security […]

[Original post on cyberpress.org]
June 22, 2026 at 7:06 AM
🎉 Open VSX 1.0.0 is here, with 1.0.1 already out! A true community milestone. Thanks to all contributors, publishers, adopters and users. 🚀
blogs.eclipse.org/post/thomas-...

#OpenVSX #VSCode #AICoding
June 18, 2026 at 9:08 AM
Trojanized Open VSX VS Code extensions were found delivering a TinyGo-compiled WebAssembly payload and using Solana memos as a takedown-resistant C2 dead drop. #GlassWASM #OpenVSX #Solana
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
Socket’s Threat Research team uncovered trojanized Open VSX Visual Studio Code extensions that delivered a TinyGo-compiled WebAssembly payload and used Solana memos as a takedown-resistant command-and-control dead drop. The campaign, attributed with medium confidence to the GlassWorm developer, was dubbed “GlassWASM” and involved packages impersonating ExarGD.vsblack and noellee-doc.flint-debug. #GlassWASM #OpenVSX #Solana #GlassWorm
www.hendryadrian.com
June 16, 2026 at 3:15 PM