Technology News

Open VSX Uncovers 77 Malicious ‘Evil Twin’ Extensions Exfiltrating Developer Data

A wave of malicious extensions impersonating legitimate developer tools has been removed from the Open VSX marketplace after researchers discovered they were silently siphoning system data.

Open VSX marketplace faced a wave of malicious activity as 77 extensions were identified that masqueraded as legitimate developer tools while silently siphoning system information.

The extensions, dubbed “evil twins,” were uploaded in a narrow window between July 26 and August 1, 2026, according to security researchers at Manifold Security.

Each package pretended to offer productivity enhancements, but once installed it would gather details about the host operating system, installed software, and active development environments.

The stolen data was then transmitted back to remote servers controlled by the attackers, allowing them to map the technical footprint of affected developers.

The malicious payloads were detected by a routine scan conducted by Open VSX’s own security team, which flagged anomalous network traffic originating from the newly submitted extensions.

Upon confirmation, the marketplace promptly removed all 77 entries from its catalog, preventing further downloads and installation.

Developers who had already installed the rogue extensions will need to uninstall them and verify that no residual components remain on their machines.

Manifold Security recommends that developers run a full system audit and update their antivirus signatures to detect any remnants of the malicious code.

Open VSX has issued a public statement urging users to review the extension list and report any suspicious activity that might not have been caught by the current removal.

The incident underscores the importance of rigorous vetting processes for open source marketplaces and the ongoing threat posed by sophisticated supply‑chain attacks.

Open VSX Uncovers 77 Malicious ‘Evil Twin’ Extensions Exfiltrating Developer Data

Open VSX marketplace faced a wave of malicious activity as 77 extensions…

Open VSX marketplace faced a wave of malicious activity as 77 extensions…

Open VSX marketplace faced a wave of malicious activity as 77 extensions were identified that masqueraded as legitimate developer tools while silently siphoning system information.

The extensions, dubbed “evil twins,” were uploaded in a narrow window between July 26 and August 1, 2026, according to security researchers at Manifold Security.

Each package pretended to offer productivity enhancements, but once inst…

Each package pretended to offer productivity enhancements, but once inst…

Each package pretended to offer productivity enhancements, but once installed it would gather details about the host operating system, installed software, and active development environments.

The stolen data was then transmitted back to remote servers controlled by the attackers, allowing them to map the technical footprint of affected developers.

The malicious payloads were detected by a routine scan conducted by Open…

The malicious payloads were detected by a routine scan conducted by Open…

The malicious payloads were detected by a routine scan conducted by Open VSX’s own security team, which flagged anomalous network traffic originating from the newly submitted extensions.

Upon confirmation, the marketplace promptly removed all 77 entries from its catalog, preventing further downloads and installation.

Developers who had already installed the rogue extensions will need to u…

Developers who had already installed the rogue extensions will need to u…

Developers who had already installed the rogue extensions will need to uninstall them and verify that no residual components remain on their machines.

Manifold Security recommends that developers run a full system audit and update their antivirus signatures to detect any remnants of the malicious code.

Open VSX has issued a public statement urging users to review the extens…

Open VSX has issued a public statement urging users to review the extens…

Open VSX has issued a public statement urging users to review the extension list and report any suspicious activity that might not have been caught by the current removal.

The incident underscores the importance of rigorous vetting processes for open source marketplaces and the ongoing threat posed by sophisticated supply‑chain attacks.