bleeping-computer · Crawled Aug 4, 2026

77 Open VSX extensions found harvesting developer info

5 IoCs
Read original article ↗

AI Summary

Manifold Security discovered a campaign involving 77 malicious extensions on the Open VSX marketplace that impersonated legitimate developer tools to harvest system and development environment metadata. These 'evil twin' extensions exfiltrated information such as hostnames, workspace paths, Git metadata, CI/CD environment details, and developer identifiers to a common infrastructure at mangorbit[.]com. While source code and credentials were not accessed, the collected data could be used to profile organizations and private repositories. The extensions used tracking identifiers, supported fallback communication via DNS TXT records, and were removed from Open VSX by August 3, 2026, though manual removal from developer systems is required.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Domain mangorbit[.]com Details →
Domain pulse[.]mangorbit[.]com Details →
Domain pulse2[.]mangorbit[.]com Details →
Domain api[.]mangorbit[.]com Details →
Domain cb[.]mangorbit[.]com Details →