Risky Bulletin Newsletter
August 13, 2025
Risky Bulletin: Crypto-thieves turn their sights to Open VSX
Presented by

News Editor
Crypto-thieves have found a new package repository to terrorize, and it's Open VSX, an independent database of Visual Studio Code extensions managed by the Eclipse Foundation.
While the VS Code editor has its official marketplace, Microsoft changed its licensing terms this year to block third-party code editors based on the original VS Code from using its marketplace to pull their extensions.
The change in policy, understandably, came after several AI-powered IDEs started cutting into VS Code's market share, all while Microsoft was paying to run and keep the VS Code marketplace online.