logo

Open VSX Unblocks 3 Extension IDs Used in Malware Campaign, Complicating Threat Tracking

ID: c6bd5158-adde-57d5-b601-0e71789698f4

STIX ID: report--c6bd5158-adde-57d5-b601-0e71789698f4

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Kavichselvan

...
...

Open VSX temporarily blocked legitimate maintainers after attackers squatted unclaimed extension IDs and published malicious lookalikes as part of a 77-extension evil‑twin campaign; three IDs (AlDuncanson.react-hooks-snippets, magne-sjaastad.opm-flow-editor-support, rumbledb.jsoniq-vscode) were unblocked between Aug 16–20 and legitimate releases subsequently published. The report documents the broader exposure (491 squatted IDs over the past year, 338 in 2026), notes Open VSX pulled the 77 malicious packages by Aug 3, and recommends tracking exact version, file hash, publisher identity, and source repo rather than relying on a flat ID denylist to mitigate supply‑chain impersonation risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.