Open VSX Removes 77 Malicious Extensions Stealing Developer Data
Open VSX, a prominent open-source extension registry, removed 77 malicious "evil twin" extensions that imitated legitimate tools to exfiltrate developer data. The campaign targeted developers by tricking them into installing compromised packages, potentially exposing credentials and sensitive information. This incident underscores the ongoing security risks within open-source marketplaces.