Researchers found 77 fake extensions in the Open VSX marketplace that posed as legitimate developer tools and secretly sent information about developers’ machines and projects to an attacker-controlled server. The "evil twin" campaign reused real extension names and listings but swapped in malicious code; 58 extensions mainly sent host and editor details, while 19 also collected workspace paths, Git remote and branch metadata, and identifiers from GitHub, GitLab, Azure DevOps, Buildkite, CircleCI, GitHub Codespaces, and Gitpod. The shared exfiltration infrastructure used mangorbit.com and related subdomains.
Why it matters: Developers and organizations using Open VSX could have leaked internal project names, repository details, and build-environment metadata even if source code and credentials were not taken. Anyone using Open VSX should remove the identified extensions, review editor and CI telemetry exposure, and check whether counterfeit packages were installed through project configuration or manual installs.
info@thehackernews.com (The Hacker News)
2026.08.05
99% relevant
This article covers the same underlying event: the removal of 77 malicious 'evil twin' extensions from the Open VSX marketplace that impersonated legitimate developer tools and exfiltrated developer environment, Git, and CI/CD metadata.
Lawrence Abrams
2026.08.04
100% relevant
This article establishes a distinct new supply-chain incident centered on a coordinated Open VSX marketplace campaign using 77 counterfeit extensions and shared exfiltration infrastructure.
← Back to all stories