hacker-news · Crawled Aug 5, 2026

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

1 IoCs
Read original article ↗

AI Summary

Open VSX removed 77 malicious 'evil twin' extensions that impersonated legitimate developer tools but were designed to exfiltrate sensitive developer environment data. The extensions, uploaded between July 26 and August 1, 2026, sent system information, workspace details, and CI/CD context to the domain mangorbit[.]com. Nineteen of them were more advanced reconnaissance payloads that collected Git metadata, installed extensions, CI environment variables, and telemetry settings. The malware included fallback mechanisms via DNS TXT records and persistence logic to distinguish between human and configuration-driven installations.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain mangorbit[.]com Details →