77 Open VSX extensions found harvesting developer info
ID: 9c402051-6a8f-56dc-a37c-e6cf13e1b091
STIX ID: report--9c402051-6a8f-56dc-a37c-e6cf13e1b091
Feed Name: Bleeping Computer
Manifold Security discovered 77 malicious "evil twin" extensions on the Open VSX marketplace that impersonated legitimate developer tools and transmitted environment and developer metadata to mangorbit.com. Most variants exfiltrated basic host and editor information, while 19 collected detailed reconnaissance (OS user/hostname, machine ID, workspace paths, Git remote/org info, branch/commit, and CI/cloud environment identifiers) that could reveal private repository names or paths. The packages were linked by shared infrastructure (pulse.mangorbit.com, pulse2.mangorbit.com, api.mangorbit.com and cb.*) and removed from Open VSX by August 3, 2026, but manual removal from affected systems is required; Manifold recommends checking extension IDs and blocking mangorbit.com.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
