Vulnerabilities

CVE Unspecified: Open VSX Extensions Harvest Developer Info

August 6, 2026 04:30 · 12 min read
CVE Unspecified: Open VSX Extensions Harvest Developer Info

Discovered Evil Twin Extensions on Open VSX Marketplace

Between July 26 and August 1, 2026, Manifold Security discovered 77 extensions on the Open VSX marketplace that were impersonating legitimate developer tools. These so-called "evil twin" extensions were transmitting information about the systems and development environments where they were installed.

Shared Infrastructure Links Extensions

Researchers linked all 77 extensions to the same activity through a shared data-exfiltration domain, as well as code and network behavior. While 58 extensions sent only a small amount of system information, the remaining 19 contained more extensive reconnaissance that exfiltrated developer, Git repository, and continuous integration (CI) metadata.

However, Manifold found that the extensions did not access source code, credentials, authentication tokens, SSH material, or browser data, and declined to speculate on the campaign's purpose. The extensions did not provide the functionality advertised in their listings and instead displayed a status bar indicator or message saying the extension was active before transmitting data to the attacker's server.

Extensions Impersonated Legitimate Tools

The packages impersonated extensions associated with a wide range of technologies and organizations, including AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and a U.S. government agency namespace. The extensions were assigned the low version number 0.0.1, while the legitimate extension's bundled extension.js file was replaced with code designed primarily to collect and transmit data.

Data Exfiltration and Collection

All 77 extensions communicated with a server at mangorbit[.]com, which was registered on July 15, 2026, eleven days before the first packages appeared. Each package included its own tracking identifier, allowing the operator to determine which counterfeit extension had been installed.

Fifty-eight of the extensions contained payloads that mainly exfiltrated the machine's hostname, with some variants also sending the workspace folder name and editor version. The other 19 extensions collected significantly more information, including the operating system username and hostname, machine identifier, editor name and version, platform architecture, locale, timezone, and the name and full filesystem path of the workspace open in the editor.

Collection of CI and Cloud Development Environment Information

The extensions also inspected some files in the workspace's .git directory to obtain Git remote hosts and organizations, the domain of the developer's configured email, the current branch, and the HEAD commit hash. They enumerated up to 60 installed extensions and collected identifiers from CI and cloud development environments, including GitHub, GitLab, Azure DevOps, Buildkite, CircleCI, GitHub Codespaces, and Gitpod.

What is unusual about this campaign is that the Open VSX listings disclosed that they collected what they called "anonymous usage metrics" and accurately said they did not access source code or credentials. However, Manifold reports that the extensions sent more data than disclosed, including CI information that could expose private repository names or paths.

Recommendations and Next Steps

Manifold recommends checking systems and workspace configuration files for extension IDs listed in its report and blocking the mangorbit[.]com domain, which is used by all 77 packages in the campaign. The packages were removed from Open VSX by August 3, 2026, but the packages would still need to be manually removed from developers' systems and applications.

Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free