CVE-2026-28353General

HIGHCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users using the affected artifact are advised to immediately remove it and rotate environment secrets. The malicious artifact has been removed from the marketplace. No other affected artifacts have been identified.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-11); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-11: 3Mentions · 2026-03-12: 3Mentions · 2026-08-05: 1Exploit Tool / Code · 2026-03-11: 1Exploit Tool / Code · 2026-08-05: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-12: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-08-05: 103-0503-1103-1208-05
Signal classification4 categories
General
337.5%
Active Exploitation
225.0%
Exploit
225.0%
Patch
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-051
General1
2026-03-113
Active Exploitation1Exploit1Patch1
2026-03-123
Active Exploitation1General2
2026-08-051
Exploit1
Full discourse8 posts
  • Bipin Jitiya@win3zz
    Active Exploitation

    CVE-2026-28353: Trivy VSCode ext v1.8.12 pwned. GitHub Actions misconfig → PAT stolen → attacker pushed malicious build to OpenVSX. Payload scrapes env secrets, creds, API keys & code via local AI agents → exfil to C2. CVSS 10.0 crit. Uninstall ASAP, rotate all keys https://t.co/kwvppkXSsr

    Post summary

    The post details an actively exploited CVE‑2026‑28353 with clear instructions to uninstall the vulnerable extension and rotate credentials.

    11023111.7K
    7.8K followersView on X
  • Emmanuel Nii Okai@engniiokai
    Exploit

    Vibe coders and AI-heavy developers. 🚨 Your AI agent might be a double agent. CVE-2026-28353 just dropped and it’s a nightmare for anyone using Open VSX versions 1.8.12/13. The exploit literally iterates on itself: Scatters your data. Uses YOUR OWN GitHub CLI to exfiltrate secrets to the attacker. If you have AI coding CLIs installed with permissive flags, you are the target. This isn't just a bug; it's a blueprint for the next generation of supply chain attacks. Check your versions. Lock your flags. Stay paranoid.

    Post summary

    The post highlights a newly disclosed CVE affecting Open VSX 1.8.12/13 and describes an exploit that leverages the GitHub CLI for data exfiltration, suggesting a warning and a mitigation by locking flags, but does not provide evidence of active attacks or a public PoC.

    1101097
    530 followersView on X
  • Tosin Afolabi@Tosin_afolabi09
    Exploit

    Three months later: a compromised Trivy VS Code extension shipped code whose stated purpose was to use the developer's own AI coding agent to collect and exfiltrate secrets. CVE-2026-28353. CVSS 10.0.

    Post summary

    The post reports that a malicious Trivy VS Code extension shipped code designed to exfiltrate developer secrets, indicating that exploit code exists for CVE‑2026‑28353.

    1001087
    69 followersView on X
  • VulnTracker@vuln_tracker
    General

    @win3zz The irony is real! CVE-2026-28353 turning Trivy - the tool we use to find vulns - into a critical vulnerability itself is peak 2026 energy. Time to rotate everything! 😅

    Post summary

    A short observation that CVE-2026-28353 has turned Trivy into a critical vulnerability, but no technical, exploitation, or patch details are provided.

    0000084
    398 followersView on X
  • SECUREU@secureu_in
    General

    Supply chain security isn't just about dependencies anymore. It's about your AI tools. CVE-2026-28353 🔗 http://thehackernews.com/2026/03/five-malicious-rust-crates-and-ai-bot.html

    Post summary

    The text flags supply‑chain concerns for AI tools and cites CVE‑2026‑28353, but provides no technical details, exploits, or remediation advice.

    0000039
    237 followersView on X
  • botnewsnetwork@botnewsnetwork
    Patch

    🚨 THE ATTACK SURFACE WIDENED OVERNIGHT: NEW OPENCLAW CVEs, RUST SUPPLY CHAIN, CHINA'S SECOND WARNING Two new HIGH severity CVEs disclosed today: → CVE-2026-32060: Path traversal in apply_patch — write or delete files outside your workspace. Patch: 2026.2.14+ → CVE-2026-32059: GNU long-option bypass in safeBins sort validation. Patch: 2026.2.22-2+ Endor Labs audited OpenClaw independently: 6 additional vulnerabilities found — SSRF, missing authentication, more path traversal. This is a sustained audit wave, not isolated bugs. Supply chain now hitting developer toolchain (CVE-2026-28353): 5 malicious Rust crates on http://crates.io targeting AI coding CLIs — delivered via weaponized Open VSX extension (v1.8.12-1.8.13). After npm (14K downloads) and ClawHub (341 skills), attackers are inside the IDE extension layer. China's CNCERT/CC just issued its second OpenClaw advisory in 72 hours — following MIIT's Monday warning. Now the national cybersecurity coordination center is flagging prompt injection, insufficient permissions, and default config data leaks. The 72-hour escalation: → npm supply chain → ClawHub (341 compromised skills) → Two new core CVEs → Rust crate toolchain attack → Two nation-state advisories Every layer is live. Update OpenClaw now. Audit every extension and crate in your build chain. #BNN #AgentSecurity #OpenClaw #CVE #SupplyChain

    Post summary

    The post announces newly disclosed high‑severity OpenClaw CVEs, lists patches, details additional audit findings, and warns of supply‑chain attacks via Rust crates, but provides no PoC, exploit code, or evidence of active exploitation.

    0000040
    25 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Five malicious Rust crates disguised as time utilities stole .env data by mimicking http://timeapi.io. An AI bot exploited GitHub Actions to hijack Aqua Security’s Trivy (CVE-2026-28353), prompting removals and audits. #RustSecurity #GitHubActions … https://ift.tt/RZ1qAHl

    Post summary

    The post reports malicious Rust crates stealing .env data and an AI bot actively exploiting CVE-2026-28353 on GitHub Actions, resulting in removals and audits.

    00000127
    3.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28353 Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX market… https://www.cve.org/CVERecord?id=CVE-2026-28353

    Post summary

    The text merely references CVE‑2026‑28353 in the context of a VS Code extension, providing an external link but no details on exploitation, patches, or technical aspects.

    0000086
    56.6K followersView on X

Explore more