The Open VSX token leak has triggered an urgent response from the Eclipse Foundation after attackers used exposed publisher tokens to upload malicious extensions. The supply-chain incident highlights ongoing risks in developer ecosystems, where compromised credentials can turn trusted tools into delivery channels for malware. How the Incident Happened Researchers identified hundreds of exposed tokens…