www.manifold.security
77 Counterfeit Open VSX Extensions Harvest Developer Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Between July 26 and August 1, 2026, 77 malicious extensions were discovered on the Open VSX marketplace, impersonating legitimate tools to harvest developer information. These 'evil twin' extensions were linked through a shared data-exfiltration domain and exhibited similar code and network behavior. While 58 of the extensions collected minimal data such as the machine's hostname, 19 of them exfiltrated detailed reconnaissance information, including Git repository metadata and CI system identifiers. The extensions were published under pseudonymous accounts, using low version numbers to mislead users. Manifold Security identified the malicious activity and reported that the extensions were removed from Open VSX as of August 3, 2026. However, the infrastructure used for the attacks remains operational. The campaign highlights the risks associated with name squatting and the need for vigilance in software installations.
Key Points: • 77 counterfeit Open VSX extensions were found harvesting developer information. • 19 extensions exfiltrated detailed reconnaissance data, including Git and CI metadata. • All malicious extensions were removed from Open VSX, but the attack infrastructure is still active.