MAL-2025-191170
Dashboard / Malicious Package / MAL-2025-191170
MAL-2025-191170
Published: 19 Nov 2025Last Modified: 26 Nov 2025
Summary: Malicious code in TretinV3.forts-api-extention (VSCode:https://open-vsx.org)
Details: Source: google-open-source-security (a765300393215437d2a27fb270964dc0a9d7d521b48fa9a541af8445f4f67be9) This extension is malicious. When installed it runs an info stealer that exfiltrates user data including credentials and cryptocurrency wallets. The extension also provides remote access and attempts to propagate itself.
References: https://www.koi.ai/blog/glassworm-first-self-propagating-worm-using-invisible-code-hits-openvsx-marketplace
Affected packages
Package
Name: TretinV3.forts-api-extention
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
0.3.1
