77 Open VSX extensions found harvesting developer info
A campaign involving 77 counterfeit extensions on the Open VSX marketplace impersonated legitimate developer tools to harvest system and development environment information. These 'evil twin' extensions transmitted metadata such as machine hostnames, workspace details, Git repository information, and continuous integration environment identifiers to a centralized server. While source code, credentials, and authentication tokens were not accessed, the collected data could enable profiling of organizations and private repositories. The malicious extensions were removed from the marketplace by August 3, 2026, but manual removal from affected systems is required.
AI Analysis
Technical Summary
Between July 26 and August 1, 2026, Manifold Security discovered 77 malicious extensions on the Open VSX marketplace that impersonated legitimate developer tools by reusing their names, namespaces, and descriptions but were published under unrelated accounts. These extensions, mostly version 0.0.1, replaced legitimate code with payloads designed to collect and exfiltrate system and development environment data to servers under the mangorbit[.]com domain. Fifty-eight extensions sent limited system information such as hostnames and workspace folder names, while 19 collected extensive metadata including OS usernames, machine identifiers, editor details, Git remote hosts, branch and commit information, and identifiers from CI and cloud development platforms like GitHub, GitLab, Azure DevOps, and others. The extensions disclosed collection of 'anonymous usage metrics' but transmitted more detailed data than stated. They did not access source code, credentials, or authentication tokens. The campaign infrastructure included multiple subdomains and fallback mechanisms for data exfiltration. The extensions were removed from Open VSX by August 3, 2026, but manual removal from developer systems is necessary.
Potential Impact
The malicious extensions exfiltrated metadata about developers' systems and development environments, including Git repository details and CI environment identifiers, which could be used to profile organizations and potentially expose private repository names or paths. No source code, credentials, authentication tokens, SSH keys, or browser data were accessed or exfiltrated. The campaign's impact is primarily related to privacy and reconnaissance rather than direct code or credential compromise.
Mitigation Recommendations
The malicious extensions were removed from the Open VSX marketplace as of August 3, 2026. However, affected developers must manually uninstall these extensions from their systems. It is recommended to check systems and workspace configuration files for the extension IDs identified by Manifold Security and to block the mangorbit[.]com domain at the network level to prevent ongoing data exfiltration.
77 Open VSX extensions found harvesting developer info
Description
A campaign involving 77 counterfeit extensions on the Open VSX marketplace impersonated legitimate developer tools to harvest system and development environment information. These 'evil twin' extensions transmitted metadata such as machine hostnames, workspace details, Git repository information, and continuous integration environment identifiers to a centralized server. While source code, credentials, and authentication tokens were not accessed, the collected data could enable profiling of organizations and private repositories. The malicious extensions were removed from the marketplace by August 3, 2026, but manual removal from affected systems is required.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Between July 26 and August 1, 2026, Manifold Security discovered 77 malicious extensions on the Open VSX marketplace that impersonated legitimate developer tools by reusing their names, namespaces, and descriptions but were published under unrelated accounts. These extensions, mostly version 0.0.1, replaced legitimate code with payloads designed to collect and exfiltrate system and development environment data to servers under the mangorbit[.]com domain. Fifty-eight extensions sent limited system information such as hostnames and workspace folder names, while 19 collected extensive metadata including OS usernames, machine identifiers, editor details, Git remote hosts, branch and commit information, and identifiers from CI and cloud development platforms like GitHub, GitLab, Azure DevOps, and others. The extensions disclosed collection of 'anonymous usage metrics' but transmitted more detailed data than stated. They did not access source code, credentials, or authentication tokens. The campaign infrastructure included multiple subdomains and fallback mechanisms for data exfiltration. The extensions were removed from Open VSX by August 3, 2026, but manual removal from developer systems is necessary.
Potential Impact
The malicious extensions exfiltrated metadata about developers' systems and development environments, including Git repository details and CI environment identifiers, which could be used to profile organizations and potentially expose private repository names or paths. No source code, credentials, authentication tokens, SSH keys, or browser data were accessed or exfiltrated. The campaign's impact is primarily related to privacy and reconnaissance rather than direct code or credential compromise.
Defensive Guidance
The malicious extensions were removed from the Open VSX marketplace as of August 3, 2026. However, affected developers must manually uninstall these extensions from their systems. It is recommended to check systems and workspace configuration files for the extension IDs identified by Manifold Security and to block the mangorbit[.]com domain at the network level to prevent ongoing data exfiltration.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/","fetched":true,"fetchedAt":"2026-08-04T19:04:17.099Z","wordCount":992}
Threat ID: 6a7237b1bf8831d53948512e
Added to database: 08/04/2026, 19:04:17 UTC
Last enriched: 08/04/2026, 19:04:46 UTC
Last updated: 08/05/2026, 00:05:04 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.