Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

tuckner

@tuckner@infosec.exchange
  • Open on infosec.exchange

Finding bad software extensions https://secureannex.com

102 Followers
160 Following
19 Posts
Joined October 31, 2022
Work:
https://secureannex.com
Blog:
https://johntuckner.me/pages/about
Location:
KC

Posts

Open post
tuckner
tuckner @tuckner@infosec.exchange · Feb 04, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

LimaCharlie released their Agentic SecOps Workspace recently which basically lets you run Claude Code in their UI which includes MCP servers. It's never been so easy to say something like 'look at my detections and research the extensions seen'. Even though 1Password falls under an unapproved password manager policy, at least it isn't malicious!

1
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Jan 31, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

RE: @tuckner@infosec.exchange

As predicted - "oorzc" a developer with extensions totalling 25,000 legitimate installs across 4 extensions looks to have had their Open VSX account compromised and published malicious updates. The worst part is this:

  1. Your extension will auto update
  2. The malicious versions will be removed from Open VSX so you won't even be able to respond effectively
  3. Your extension will not downgrade itself leaving the malicious version active
  4. Victims will have to wait until the real developer publishes a new version in order for an auto update to be triggered.
  5. Even if the extensions are removed from the marketplace, they won't uninstall

What a mess and this isn't the first time this has happened!

oorzc.mind-map@1.0.61
oorzc.i18n-tools-plus@1.6.8
oorzc.ssh-tools@0.5.1 (removed)
oorzc.scss-to-css-compile@1.3.4

Extension analysis located here:
https://app.secureannex.com/extensions/investigate?collection=extensions&page=1&page_size=25&platform=openvsx&field=owner&value=oorzc

1
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Jan 28, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

The next supply chain worm has been seeded in Open VSX. A cloned Angular extension with 5000 downloads has been available for two weeks and was updated with malware 6 days ago. This multi stage attack uses etherhiding, gcal c2, rust implants, and more.

https://annex.security/blog/worms-lurking/

0
1
0
1
Open post
tuckner
tuckner @tuckner@infosec.exchange · Jan 19, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

If you've had to listen to me over the last couple months, it's likely you would've hear me say that all of our most important apps will have extensions or plugins for integration. Think we're learning from past mistakes?

1
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Jan 16, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

A browser extension, PasteReady, was listed for sale last May became malicious after an ownership transfer on December 27th. Many organizations have been impacted by extensions which changed hands. @secureannex.com watches for transfers and warns you in advance!

https://www.linkedin.com/pulse/pasteready-danger-sold-extensions-john-tuckner-3x9pc/?trackingId=2SQl5CStSZaQ9b65g0cxnQ%3D%3D

2
0
1
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Jan 14, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Pyrefly - Python Language Tooling by Meta is the 4th most used extension in Open VSX. Be careful downloading the 'Pro' version in Cursor hoping you'll get some extra features, it is published by 'casendsabotnu954' who just joined GitHub the other day. Textbook cloning and staging behavior!

0
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Jan 08, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Loving a new detection that identifies code extensions published by new and lightly used GitHub accounts.This time it instantly caught an extension impersonating JFrog which already has over 10k downloads.

0
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Jan 05, 2026
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Not the "pulling a Rabbit out of a hat" magic trick that most want. This Firefox extension completely changes from a "Simple Label Editor" to a Rabby wallet stealer overnight.

Your browser does not support the video tag.
0
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 29, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

A browser extension with over a million users is poaching the prompts of leading AI chat tools.

SimilarWeb loads obfuscated remote configuration to collect the prompts, responses and metadata of your conversations. Your private thoughts are analytics companies gain.

https://secureannex.com/blog/prompt-poaching

0
0
1
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 17, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

These code comments are an improvement from:

  1. Request malware
  2. Download malware
  3. Make malware executable
  4. Run malware

This is the extent of the extension available in the VS Marketplace. Installs a Mythic agent from the C2.

0
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 10, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Monitoring a large influx of AI slop extensions that are reposting a marginally refactored but known malicious package. The marketplace listings are packed with emojis and a couple sections of 'features'. This one made the mistake of linking to an already known piece of malware. If any are not immediately malicious, they will soon update with exploit code.

0
0
1
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 09, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Welcome to Antigravity the newest most advanced agentic AI development tool by Google...

... uses Open VSX for extensions and shows malicious listings to users.

0
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 05, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Changing how an extension looks in a marketplace doesn't require new code to be pushed. Check out the magic when this "Test Extension" magically turns into a "solidity" extension after being published. Review the full lineage of a marketplace listing using the new date picker in Secure Annex.

Your browser does not support the video tag.
1
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 05, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Vibed coded malicious extensions are getting out of hand!

This 'theme' downloads a malicious zip, unpacks it, and runs it silently with PowerShell.

1
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 02, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

16 Firefox extensions with the almost the same name, same permhash requesting the most sensitive permission combinations like and cookies. Something being staged?

0
0
1
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Dec 01, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Glassworm returned in a big way during the holiday. We're tracking 23 code extensions across the VS Marketplace and Open VSX which copy popular extensions, evade filters, manipulate their download counts, and then update with sinister malware.

https://secureannex.com/blog/glassworm-continued

1
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Nov 28, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Unprecedented code extension attacks this week. All are name squatting on popular tools. Only a couple have had malware deployed, many are still staging, few have been removed from marketplaces. There may be more coming.

VS Marketplace:
iconkieftwo.icon-theme-materiall
prisma-inc.prisma-studio-assistance
prettier-vsc.vsce-prettier
flutcode.flutter-extension
csvmech.csvrainbow
codevsce.codelddb-vscode
saoudrizvsce.claude-devsce
clangdcode.clangd-vsce
cweijamysq.sync-settings-vscode
bphpburnsus.iconesvscode
klustfix.kluster-code-verify
vims-vsce.vscode-vim
yamlcode.yaml-vscode-extension
solblanco.svetle-vsce

Open VSX:
saoudrizvsce.claude-dev
saoudrizvsce.claude-devsce
vitalik.solidity

2
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Nov 27, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

@badsamurai@infosec.exchange @cR0w@infosec.exchange yep have seen some indications of intercepting chats. Haven't investigated deeply yet. Two patterns are removing CORS headers to embed chatgpt in the extension and also proxying openai API calls.

3
0
0
0
Open post
tuckner
tuckner @tuckner@infosec.exchange · Nov 24, 2025
tuckner
@tuckner@infosec.exchange

Finding bad software extensions https://secureannex.com

infosec.exchange

Imagine how useful it would be if the Chrome Web Store showed you users over time. This ad blocker went from 0 to 40,000 users overnight! 🤔

0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 12:05:12 UTC