Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

77 malicious extensions found on Open VSX marketplace

  • What: 77 malicious extensions found on Open VSX marketplace
  • Impact: Developers and users at risk of data exfiltration
Read Full Article →

Malware 77 malicious extensions found on Open VSX marketplace August 5, 2026 Share By SC Staff Seventy-seven malicious extensions impersonating legitimate developer tools were discovered on the Open VSX marketplace, transmitting system and development environment information. The campaign, dubbed "evil twin," was identified by Manifold Security between July 26 and Aug. 1, 2026, with all malicious extensions linked through shared infrastructure and code. The extensions did not access source code or credentials, but their purpose remains speculative, with further coverage provided by Bleeping Computer. The "evil twin" campaign involved 77 extensions on the Open VSX marketplace that mimicked legitimate tools but were published under unrelated accounts. While 58 extensions exfiltrated basic system information like hostname, the remaining 19 conducted more extensive reconnaissance. These 19 extensions collected operating system details, machine identifiers, editor information, Git repository metadata, and identifiers from CI/cloud development environments such as GitHub and Azure DevOps. All 77 extensions communicated with a shared domain, mangorbit[.]com. Although the extensions claimed to collect only anonymous usage metrics and stated they did not access source code or credentials, they transmitted more data than disclosed. The packages were removed from the marketplace by Aug. 3, 2026, but developers must manually remove them from their systems. Manifold Security recommends blocking the mangorbit[.]com domain and checking for suspicious extension IDs. Source: Bleeping Computer SC Staff Related Malware AI-driven cybercrime surges in Africa, accounting for 55% of reported digital crime SC Staff August 5, 2026 AI-driven cybercrime now constitutes 55% of all reported digital crime in Africa, according to a new report from Interpol. Malware New npm packages deliver remote access trojan targeting Alibaba developers SC Staff August 4, 2026 A new set of malicious npm packages were discovered targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT). Malware Fake Roblox Xeno executor installers distribute malware SC Staff August 4, 2026 Fake Xeno Executor installers are targeting Roblox players with malware that provides remote access and steals sensitive information. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article