By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Open VSX Removes 77 Malicious Extensions Stealing Developer Data

The Open VSX marketplace has removed 77 malicious extensions that were designed to impersonate legitimate developer tools and exfiltrate sensitive data from users' systems. These "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, as reported by Manifold Security. The primary function of these malicious packages was to collect and transmit information about the systems and development environments on which they were installed. This data could include details about the user's operating system, installed software, project configurations, and potentially even sensitive credentials or code snippets.
Manifold Security's analysis revealed that the extensions were crafted to appear as trusted tools, likely leveraging similar names, icons, or descriptions to deceive developers into installing them. The malicious code within these extensions would then activate upon installation, silently gathering telemetry and system information. This information is valuable to attackers for various purposes, including identifying potential targets for further exploitation, understanding a developer's workflow to craft more convincing phishing attacks, or gathering intelligence for supply chain attacks. The rapid upload of such a large number of malicious extensions within a short timeframe highlights the ongoing threat posed by malicious actors targeting software development ecosystems.
Open VSX, a popular open-source registry for Visual Studio Code extensions, serves as a critical platform for developers to discover and integrate tools that enhance their productivity. The presence of such a significant number of malicious extensions underscores the challenges in maintaining the security and integrity of open-source software repositories. While the extensions have been removed, the incident serves as a stark reminder for developers to exercise caution when installing third-party extensions, even from seemingly reputable sources. Verifying the publisher, checking reviews, and scrutinizing the permissions requested by an extension are crucial steps in mitigating the risk of compromise. The incident also puts pressure on platform maintainers like Open VSX to strengthen their vetting processes and implement more robust security measures to detect and prevent the distribution of malicious software.
The discovery and subsequent removal of these 77 extensions by Manifold Security demonstrate the importance of proactive threat intelligence and security research within the open-source community. By identifying and reporting these threats, security firms play a vital role in protecting developers and the broader software supply chain. The speed at which these extensions were uploaded and the sheer volume suggest a coordinated effort by malicious actors. The investigation into the full extent of data exfiltrated and the specific types of information targeted is likely ongoing. This event reinforces the need for continuous vigilance and collaboration between security researchers, platform providers, and the developer community to combat evolving cyber threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.