Fake Open VSX Extensions Harvest Private Repo and CI Data
2026-08-05T20:52:07Z•f0c67096e3ac9d4bc8e4cdc6b45c2c7bb3af30e8510a4c9f74a5a2736a7b19ea
ai-securityaitmchromecloud-securitycryptominingdata-breachexploitationidentity-attackslinuxllm-securitymalvertisingmalwarenation-statenorth-korea-linked-threat-actornpmopen-vsxphishingprompt-injectionransomwareremote-access-trojansaas-securitysupply-chainthreat-intelligencevulnerabilityzero-day
What happened
Infosecurity Magazine feed covering active cyber threats, vulnerabilities, data breaches, phishing and malware campaigns, software supply-chain compromises, ransomware, cloud and identity attacks, and emerging AI security risks. Highlights include malicious Open VSX and npm extensions, unauthenticated Paperclip AI command execution, phishing-enabled remote access, WhatsApp account hijacking, rapid exploitation of newly disclosed vulnerabilities, loader evasion, Linux privilege escalation, and malicious model repositories. Several reports describe high-impact incidents affecting organizations,—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- f0c67096e3ac9d4bc8e4cdc6b45c2c7bb3af30e8510a4c9f74a5a2736a7b19ea
- Enrichment time
- 2026-08-05T20:52:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.