Redhotcyber
Malware Campaign Targets Open VSX Extension with 5,066 Downloads
First seen 30 Jan 2026, 19:15 UTC
•



+12
•80% similarity
•36.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A sophisticated malware campaign has compromised the Open VSX extension marketplace, affecting over 5,000 developer workstations. The malicious package masqueraded as a legitimate Angular Language Service extension, embedding encrypted malware that activates upon opening HTML or TypeScript files. The attack utilized typosquatting and steganography techniques to evade detection.
ThreatCluster AI
How this analysis works