MAL-2026-2230
Dashboard / Malicious Package / MAL-2026-2230
MAL-2026-2230
Published: 26 Mar 2026Last Modified: 26 Mar 2026
Summary: Malicious code in aquasecurityofficial.trivy-vulnerability-scanner (VSCode:https://open-vsx.org)
Details: Source: google-open-source-security (b6cab1dae06f51e2aaa57704d8374b6882440070d0796e7b719a85e6f803888b) This extension is a compromised version of the offical Trivy VSCode extension available on the Microsoft Marketplace. Versions 1.8.11 and earlier uploaded to OpenVSX are non-malicious. Malicious behavior was added in v1.8.12 and further refined in v1.8.13. The extension attempts to run various AI tools with a prompt designed to gather sensitive information, and publish it via a GitHub repository.
Affected packages
Package
Name: aquasecurityofficial.trivy-vulnerability-scanner
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.8.12
1.8.13
