logo

77 Open VSX extensions found harvesting developer info

ID: 9c402051-6a8f-56dc-a37c-e6cf13e1b091

STIX ID: report--9c402051-6a8f-56dc-a37c-e6cf13e1b091

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Lawrence Abrams

...
...

Manifold Security discovered 77 malicious "evil twin" extensions on the Open VSX marketplace that impersonated legitimate developer tools and transmitted environment and developer metadata to mangorbit.com. Most variants exfiltrated basic host and editor information, while 19 collected detailed reconnaissance (OS user/hostname, machine ID, workspace paths, Git remote/org info, branch/commit, and CI/cloud environment identifiers) that could reveal private repository names or paths. The packages were linked by shared infrastructure (pulse.mangorbit.com, pulse2.mangorbit.com, api.mangorbit.com and cb.*) and removed from Open VSX by August 3, 2026, but manual removal from affected systems is required; Manifold recommends checking extension IDs and blocking mangorbit.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.