Evil Twin is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
Evil Twin is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed August 4, 2026; most recent activity August 4, 2026.
Between July 26 and August 1, 2026, 77 malicious extensions were discovered on the Open VSX marketplace, impersonating legitimate tools to harvest developer information. These 'evil twin' extensions were linked through…
Evil Twin is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning Evil Twin on ThreatCluster is dated August 4, 2026.
Across ThreatCluster reporting, Evil Twin most frequently co-occurs with Data Breach, Open VSX, T1041 - Exfiltration Over C2 Channel, T1071 - Application Layer Protocol, T1195 - Supply Chain Compromise, among 12 tracked related entities.
The most significant recent cluster is “77 Counterfeit Open VSX Extensions Harvest Developer Data” (2 articles · Updated August 4, 2026). Evil Twin appears across 1 threat cluster in total, listed above with sources.
Evil Twin appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.