Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces

Fake Open VSX extensions have hijacked high‑trust namespaces like AMD, Azure, Salesforce, Hyperledger, and a U.S. government agency on the Open VSX Registry, silently harvesting Git and CI metadata from developer and CI environments while posing as legitimate tools. Each package cloned the name, namespace, and description of a real, unrelated extension and re‑published it […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: