Security News Open VSX rotates tokens used in supply-chain malware attack BleepingComputer Daniel Bender 02 Nov 2025 The Open VSX registry rotated access tokens after they were accidentally leaked by developers in public repositories and allowed threat actors to publish malicious extensions in an attempted supply-chain attack.