A Large-Scale Campaign of Malicious Extensions Spotted on Open VSX Marketplace
In a disturbing discovery, cybersecurity researchers at Manifold Security have unearthed a massive campaign of malicious extensions spreading across the Open VSX marketplace. Dubbed an “evil twin” operation, 77 counterfeit packages have been identified, impersonating legitimate developer tools and harvesting sensitive information from affected systems.
These fake extensions were published on Open VSX between July 26 and August 1, 2026, targeting a wide range of technologies and organizations, including AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and even a U.S. government agency namespace. What’s particularly alarming is that these malicious packages reused the names, namespaces, and descriptions of real Open VSX extensions, making them nearly indistinguishable from their legitimate counterparts.
The extensions displayed a status bar indicator or message claiming to be active before transmitting collected data to the attacker’s server at mangorbit[.]com. Each package included its own tracking identifier, allowing the operator to monitor which counterfeit extension had been installed. The malicious code was designed primarily to collect and transmit system information, including hostname, operating system username and hostname, machine identifier, editor name and version, platform architecture, locale, timezone, and the name and full filesystem path of the workspace open in the editor.
Of the 77 extensions, 58 sent only basic system information, while the remaining 19 contained more extensive reconnaissance data. These “reconnaissance” extensions exfiltrated developer, Git repository, and continuous integration (CI) metadata, including CI information that could potentially expose private repository names or paths. Some variants even checked whether they had been installed manually or automatically through a project configuration.
What’s unusual about this campaign is that the Open VSX listings disclosed collecting “anonymous usage metrics” and accurately stated they did not access source code or credentials. However, Manifold reports that the extensions sent more data than disclosed, highlighting a worrying trend of overcollection by malicious actors.
The implications are significant: these malicious packages could potentially profile organizations, development environments, and private repositories based on collected metadata. As researchers at Manifold Security caution, even if the extensions have been removed from Open VSX, developers must still manually remove them from their systems and applications.
In light of this discovery, it’s crucial for developers to remain vigilant when installing extensions from marketplaces like Open VSX. Always scrutinize the package details, check the publisher’s reputation, and be wary of low version numbers or suspicious code behavior. Furthermore, regularly reviewing system logs and monitoring network activity can help detect potential malicious activity early on.
Source: Bleeping Computer — 2026-08-04