Interestana
Home/News/77 Open VSX Extensions Harvested Developer Data
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

77 Open VSX Extensions Harvested Developer Data

Security researchers have identified 77 malicious extensions on the Open VSX marketplace that were designed to impersonate legitimate developer tools while secretly harvesting sensitive information from users' systems and development environments. These extensions were found to be transmitting details about the operating system, installed software, and configuration settings of the machines they were running on. The Open VSX marketplace is an open-source alternative to the Visual Studio Code Marketplace, aiming to provide a more permissive platform for extensions.

The discovery was made by researchers from ReversingLabs, who detailed their findings in a report published on March 20, 2024. The malicious extensions employed various techniques to evade detection, including obfuscating their code and using seemingly innocuous names that mimicked popular developer utilities. Upon installation, these extensions would collect data such as the user's operating system version, installed applications, environment variables, and potentially even sensitive configuration files related to their development workflows. This information could then be used for various malicious purposes, including targeted attacks, credential theft, or further exploitation of vulnerabilities.

ReversingLabs stated that the extensions were actively transmitting this data to remote servers controlled by the attackers. The specific details of the exfiltrated data included information about the user's machine architecture, installed packages, and potentially even source code repository configurations. The researchers emphasized that the scale of the operation, with 77 distinct malicious extensions identified, suggests a coordinated effort to compromise developers' systems. The Open VSX marketplace, while offering an open alternative, also presents a potential attack vector if security vetting processes are not robust enough.

Following the disclosure by ReversingLabs, the Open VSX team has taken action to remove the identified malicious extensions from their platform. However, the incident highlights ongoing security challenges within software marketplaces, particularly those that host third-party extensions and plugins. Developers often rely on these extensions to enhance their productivity and integrate various tools into their workflows, making them prime targets for attackers seeking to gain access to valuable development assets and sensitive information. The researchers have not yet disclosed the specific names of the malicious extensions or the command-and-control servers used, but the investigation is ongoing to understand the full scope of the compromise and identify any potential accomplices or related campaigns.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next