The Eclipse Foundation says it contained the GlassWorm that was spreading on OpenVSX.

It also rotated creds for a bunch of developers that leaked their OpenVSX publishing tokens.

https://blogs.eclipse.org/post/mika%C3%ABl-barbero/open-vsx-security-update-october-2025