Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Overview
Researchers have identified 77 malicious extensions on the Open VSX marketplace that were designed to mimic legitimate developer tools. These 'evil twin' extensions were uploaded between July 26 and August 1, 2026, and were found to be exfiltrating sensitive information about the systems and development environments where they were installed. The extensions have since been removed from the marketplace. This incident raises concerns for developers who may have unknowingly installed these malicious tools, as their data and system information could have been compromised. Developers should remain vigilant and ensure they are using verified extensions to protect their environments.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Open VSX marketplace extensions, developer tools
- Action Required: Extensions removed from Open VSX marketplace.
- Timeline: Newly disclosed
Original Article Summary
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
Impact
Open VSX marketplace extensions, developer tools
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Extensions removed from Open VSX marketplace
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.