Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Trivy VS Code extension 1.8.12 on OpenVSX compromised to exfiltrate secrets via AI agent

Version 1.8.12 of the Trivy Vulnerability Scanner VS Code extension distributed through the OpenVSX marketplace was compromised and contained malicious code that used the local AI coding agent to collect and exfiltrate sensitive information. The malicious artifact has been removed from the marketplace and users are advised to remove it and rotate environment secrets.

Disclosed 5 March 2026 · Record updated 13 September 2026

Impact

Users who installed the compromised extension version may have had environment secrets and other sensitive information collected and exfiltrated via their local AI coding agent; secret rotation advised.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-28353