OpenVSX crypto-stealing worms are actively targeting developers by abusing trust in open-source extension marketplaces. Security researchers have uncovered malicious Visual Studio Code extensions distributed through the Open VSX registry that secretly deploy malware designed to steal credentials and cryptocurrency assets. The campaign highlights how developer environments have become high-value targets for attackers seeking long-term access…