logo

Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign

ID: b096f0d4-803d-5e46-9f53-5a25bc11c079

STIX ID: report--b096f0d4-803d-5e46-9f53-5a25bc11c079

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Mayura Kathir

...
...

An evil‑twin campaign published 77 counterfeit VS Code extensions on Open VSX by registering unclaimed extension names and pushing low-version malicious packages (many at 0.0.1) under unauthorized accounts. Nineteen of the samples included reconnaissance code that collected host/editor metadata plus Git and CI/CD context (remote hosts, orgs, commit emails, branches, commit hashes, workspace paths, installed extensions, CI identifiers), risking disclosure of private repository paths and CI information. Open VSX removed the malicious IDs but restored three identifiers when legitimate maintainers reclaimed them, exposing a blocklist gap: identifier-only blocking cannot distinguish historical malicious packages from later legitimate releases. The incident underscores the need to retain artifact-specific indicators (version, VSIX hash, publisher, repo, first-seen date) and for maintainers to claim namespaces proactively.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.