Close Menu
TechurzTechurz
    What's Hot

    Snap alums unveil Ghost Angels fund

    May 30, 2026

    As the browser wars heat up, here are the hottest alternatives to Chrome and Safari in 2026

    May 30, 2026

    After Nvidia’s $20B not-acqui-hire, AI chip startup Groq reportedly raising $650M

    May 29, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Snap alums unveil Ghost Angels fund
    • As the browser wars heat up, here are the hottest alternatives to Chrome and Safari in 2026
    • After Nvidia’s $20B not-acqui-hire, AI chip startup Groq reportedly raising $650M
    • After Nvidia’s $20B not-aqui-hire, AI chip startup Groq reportedly raising $650M
    • Cognition’s Scott Wu says AI coding agents shouldn’t replace humans
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
    Cyber Reality

    Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery

    TechurzBy TechurzNovember 1, 2025Updated:May 10, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Open VSX Tokens
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 31, 2025Ravie LakshmananMalware / Secure Coding

    Eclipse Foundation, which maintains the open-source Open VSX project, said it has taken steps to revoke a small number of tokens that were leaked within Visual Studio Code (VS Code) extensions published in the marketplace.

    The action comes following a report from cloud security company Wiz earlier this month, which found several extensions from both Microsoft’s VS Code Marketplace and Open VSX to have inadvertently exposed their access tokens within public repositories, potentially allowing bad actors to seize control and distribute malware, effectively poisoning the extension supply chain.

    “Upon investigation, we confirmed that a small number of tokens had been leaked and could potentially be abused to publish or modify extensions,” Mikaël Barbero, head of security at the Eclipse Foundation, said in a statement. “These exposures were caused by developer mistakes, not a compromise of the Open VSX infrastructure.”

    Open VSX said it has also introduced a token prefix format “ovsxp_” in collaboration with the Microsoft Security Response Center (MSRC) to make it easier to scan for exposed tokens across public repositories.

    Furthermore, the registry maintainers said they have identified and removed all extensions that were recently flagged by Koi Security as part of a campaign named “GlassWorm,” while emphasizing that the malware distributed through the activity was not a “self-replicating worm” in that it first needs to steal developer credentials in order to extend its reach.

    “We also believe that the reported download count of 35,800 overstates the actual number of affected users, as it includes inflated downloads generated by bots and visibility-boosting tactics used by the threat actors,” Barbero added.

    Open VSX said it’s also in the process of enforcing a number of security changes to bolster the supply chain, including –

    • Reducing the token lifetime limits by default to reduce the impact of accidental leaks
    • Making token revocation easier upon notification
    • Automated scanning of extensions at the time of publication to check for malicious code patterns or embedded secrets

    The new measures to strengthen the ecosystem’s cyber resilience come as the software supplier ecosystem and developers are increasingly becoming the target of attacks, allowing attackers far-reaching, persistent access to enterprise environments.

    “Incidents like this remind us that supply chain security is a shared responsibility: from publishers managing their tokens carefully, to registry maintainers improving detection and response capabilities,” Barbero said.

    discovery Eclipse Foundation leaked Open Revokes tokens VSX Wiz
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis tank of a phone has a built-in projector, but that’s not why you should care about it
    Next Article My Sonos Arc Ultra faced an unexpected challenger – and the soundbar met its match
    Techurz
    • Website

    Related Posts

    Cyber Reality

    Digital Identity Protection: 7 Hidden Risks Most Users Miss

    May 25, 2026
    Cyber Reality

    Neural Data Policy: 7 Risks That Brain Privacy Laws Miss

    May 25, 2026
    Cyber Reality

    How AI Changing Cyber Crime: 7 Critical Shifts to Watch

    May 25, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,289

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202620

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202518
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.