www.manifold.security
77 Counterfeit Open VSX Extensions Harvest Developer Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Between July 26 and August 1, 2026, 77 counterfeit extensions were discovered on the Open VSX marketplace, impersonating legitimate tools and harvesting sensitive developer information. These extensions, linked to a shared data-exfiltration domain, were identified by Manifold Security. Most of the extensions sent minimal data, such as machine hostnames, while 19 of them exfiltrated detailed reconnaissance data, including Git repository and continuous integration metadata. The packages were published under unrelated accounts, using low version numbers and mimicking real extensions from trusted organizations like AMD and Azure. The malicious extensions were removed from Open VSX on August 3, but the associated infrastructure remained active. The campaign highlights the risks of automated name resolution in software installations, where counterfeit packages can be indistinguishable from legitimate ones.
Key Points: • 77 counterfeit extensions on Open VSX harvested sensitive developer data. • 19 extensions exfiltrated detailed Git and CI metadata, posing significant risks. • The malicious packages were removed, but the infrastructure remains active.