MAL-2026-2230

    Dashboard / Malicious Package / MAL-2026-2230

    MAL-2026-2230

    Published: 26 Mar 2026Last Modified: 26 Mar 2026

    Summary: Malicious code in aquasecurityofficial.trivy-vulnerability-scanner (VSCode:https://open-vsx.org)

    Details: Source: google-open-source-security (b6cab1dae06f51e2aaa57704d8374b6882440070d0796e7b719a85e6f803888b) This extension is a compromised version of the offical Trivy VSCode extension available on the Microsoft Marketplace. Versions 1.8.11 and earlier uploaded to OpenVSX are non-malicious. Malicious behavior was added in v1.8.12 and further refined in v1.8.13. The extension attempts to run various AI tools with a prompt designed to gather sensitive information, and publish it via a GitHub repository.

    Affected packages

    Package

    Name: aquasecurityofficial.trivy-vulnerability-scanner

    Purl:

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.8.12
    1.8.13
    MAL-2026-2230 | CVE-DB