Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign
ID: b096f0d4-803d-5e46-9f53-5a25bc11c079
STIX ID: report--b096f0d4-803d-5e46-9f53-5a25bc11c079
Feed Name: GBHackers
An evil‑twin campaign published 77 counterfeit VS Code extensions on Open VSX by registering unclaimed extension names and pushing low-version malicious packages (many at 0.0.1) under unauthorized accounts. Nineteen of the samples included reconnaissance code that collected host/editor metadata plus Git and CI/CD context (remote hosts, orgs, commit emails, branches, commit hashes, workspace paths, installed extensions, CI identifiers), risking disclosure of private repository paths and CI information. Open VSX removed the malicious IDs but restored three identifiers when legitimate maintainers reclaimed them, exposing a blocklist gap: identifier-only blocking cannot distinguish historical malicious packages from later legitimate releases. The incident underscores the need to retain artifact-specific indicators (version, VSIX hash, publisher, repo, first-seen date) and for maintainers to claim namespaces proactively.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
