TI Mindmap HUB
Threat Intelligence Report

Unauthorized AI Agent Execution Code Published to OpenVSX in Aqua Trivy VS Code Extension

๐Ÿ“… March 2, 2026 ๐Ÿ“ฐ socket.dev ๐Ÿ” 0 CVE(s) referenced

Malicious versions of the Aqua Trivy VS Code extension were published to OpenVSX, covertly injecting prompts that hijack local AI coding assistants to perform system reconnaissance and attempt data exfiltration, marking a novel and stealthy AI-driven supply chain attack.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle