Eclipse Foundation, which maintains the open-source Open VSX project, said it has taken steps to revoke a small number of tokens that were leaked within Visual Studio Code (VS Code) extensions published in the marketplace.
The action comes following a report from cloud security company Wiz earlier this month, which found several extensions from both Microsoft's VS Code Marketplace and Open VSX to have inadvertently exposed their access tokens within public repositories, potentially allowing bad actors to seize control and distribute malware, effectively poisoning the extension supply chain.
"Upon investigation, we confirmed that a small number of tokens had been leaked and could potentially be abused to publish or modify extensions," Mikaël Barbero, head of security at the Eclipse Foun

 The Hacker News
 The Hacker News

 FOX 13 Tampa Bay Crime
 FOX 13 Tampa Bay Crime PC World Business
 PC World Business Fast Company Lifestyle
 Fast Company Lifestyle Crooks and Liars
 Crooks and Liars Raw Story
 Raw Story AlterNet
 AlterNet Cleveland Jewish News
 Cleveland Jewish News 5 On Your Side Sports
 5 On Your Side Sports