Malicious Code in Trivy Vulnerability Scanner Extension for VS Code by Aqua Security
CVE-2026-28353
10CRITICAL
What is CVE-2026-28353?
The Trivy VS Code Extension version 1.8.12 was compromised, containing malicious code that exploited a local AI coding agent to collect and exfiltrate sensitive information. Users who installed the affected version are strongly advised to remove it immediately and rotate any compromised environment secrets. The dangerous extension has since been removed from the OpenVSX marketplace, with no additional affected artifacts reported at this time.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
trivy-vscode-extension = 1.8.12
