Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces
ID: 8689653f-43aa-5a92-ab67-d650e5eeb659
STIX ID: report--8689653f-43aa-5a92-ab67-d650e5eeb659
Feed Name: GBHackers
Manifold Security discovered 77 counterfeit Open VSX extensions impersonating legitimate publishers (including high‑trust namespaces) that silently beacon developer and CI metadata to mangorbit.com. Variants include lightweight beacons and larger reconnaissance payloads that exfiltrate hostnames, workspace paths, Git remotes, branch and commit SHAs, and CI repository identifiers; extensions used retry logic and a DNS TXT fallback to maintain collection after takedown. Open VSX has removed the listings, but any deployed/pinned extensions continue to run and report data, and IOCs include domain mangorbit.com, subdomains (pulse/api/cb.*), paths (/api/v1/metrics, /api/v1/events, /t/<id>), a _beacon TXT lookup, and user-agent vscode-ext-metrics/1.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
