77 Open VSX extensions found harvesting developer info
AI Summary
Manifold Security discovered a campaign involving 77 malicious extensions on the Open VSX marketplace that impersonated legitimate developer tools to harvest system and development environment metadata. These 'evil twin' extensions exfiltrated information such as hostnames, workspace paths, Git metadata, CI/CD environment details, and developer identifiers to a common infrastructure at mangorbit[.]com. While source code and credentials were not accessed, the collected data could be used to profile organizations and private repositories. The extensions used tracking identifiers, supported fallback communication via DNS TXT records, and were removed from Open VSX by August 3, 2026, though manual removal from developer systems is required.
AI-extracted · verify before operational use