Manifold Security identified 77 malicious extensions on the Open VSX marketplace, uploaded between July 26 and August 1, 2026. These extensions, dubbed "evil twins," impersonated legitimate developer tools. All 77 packages were removed from Open VSX on August 3, 2026.
The extensions transmitted information about the systems and development environments where they were installed. While 58 extensions sent basic system information like the machine's hostname, the remaining 19 performed more extensive reconnaissance. These 19 extensions exfiltrated developer, Git repository, and continuous integration (CI) metadata, including local hostname, operating system username, editor name and version, platform, architecture, locale, timezone, and the open workspace's folder name and full file system path.
Manifold Security confirmed that the extensions did not access source code, credentials, authentication tokens, SSH material, or browser data.
Manifold Security linked all 77 extensions to the same activity through a shared data-exfiltration domain, as well as common code and network behavior. The "evil twin" packages reused the names, namespaces, and descriptions of real Open VSX extensions but were published through unrelated accounts.
This incident highlights ongoing supply chain risks within developer tool marketplaces. The use of counterfeit packages to trick users into installing malicious software represents a method for data collection from developer environments.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Open VSX removed 77 malicious extensions that impersonated legitimate developer tools and exfiltrated system and development environment information. These "evil twin" extensions were uploaded between July 26 and August 1, 2026, and collected data ranging from hostnames to detailed machine descriptions and open repository information. This incident highlights ongoing supply chain risks in developer tool marketplaces.
Manifold Security discovered 77 malicious extensions on the Open VSX marketplace that mimicked legitimate developer tools and transmitted system and development environment data. These "evil twin" extensions collected information like hostnames, workspace folders, editor versions, and in some cases, Git repository and CI metadata, but did not access source code or credentials.