Product
OpenVSX
- First Reported
- Sep 30, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (1)
- attack started with a Pwn Request to exfiltrate a CI token, then deployed the worm through a malicious OpenVSX extension. The other attack targeted projects like Zapier, PostHog, and Postman by exploiting long-lived Retrospective: How Malicious Software Updates Poison Development Environments
Malware (7)
Threat Actors (3)
MITRE ATT&CK (5)
Vendors (3)
Products (8)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.