logo

Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces

ID: 8689653f-43aa-5a92-ab67-d650e5eeb659

STIX ID: report--8689653f-43aa-5a92-ab67-d650e5eeb659

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Mayura Kathir

...
...

Manifold Security discovered 77 counterfeit Open VSX extensions impersonating legitimate publishers (including high‑trust namespaces) that silently beacon developer and CI metadata to mangorbit.com. Variants include lightweight beacons and larger reconnaissance payloads that exfiltrate hostnames, workspace paths, Git remotes, branch and commit SHAs, and CI repository identifiers; extensions used retry logic and a DNS TXT fallback to maintain collection after takedown. Open VSX has removed the listings, but any deployed/pinned extensions continue to run and report data, and IOCs include domain mangorbit.com, subdomains (pulse/api/cb.*), paths (/api/v1/metrics, /api/v1/events, /t/<id>), a _beacon TXT lookup, and user-agent vscode-ext-metrics/1.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.