Find notable cyber news and cases, enriched with sources, timelines, and signals.

Open VSX evil twin extension data-harvesting campaign

Campaign
First reported
Last updated
Happening score
H score 41
3 unique sources, 3 articles

Summary

Hide ▲

Open VSX hosted an evil twin campaign that used 77 counterfeit extensions to impersonate legitimate developer tools and transmit host and workspace data to mangorbit[.]com. The extensions were uploaded between July 26 and August 1, 2026 and removed from the marketplace on August 3, 2026. Researchers said 58 packages mainly sent host-level data, while 19 collected deeper Git and CI metadata from developer environments. The operation reused real extension names, namespaces, and descriptions, and some packages also reported workspace and editor details before exfiltration.

Related Happenings

StegoAd malicious Edge extension operation

Malware Activity
H score19 First: 29.06.2026 11:32 Last: 29.06.2026 11:32 Sources 1

About this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...

JetBrains Marketplace malicious plugin API-key theft campaign

Campaign
H score15 First: 17.06.2026 00:54 Last: 17.06.2026 00:54 Sources 1

About this happening: A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...

Miasma software supply chain campaign expands to new PyPI wave

Campaign
H score29 First: 09.06.2026 19:34 Last: 09.06.2026 19:34 Sources 1

About this happening: The Miasma supply-chain campaign has expanded into a new PyPI wave, increasing the risk that developers and downstream users will ingest information-stealing malware t...

GlassWorm supply-chain malware activity

Malware Activity
H score22 First: 27.05.2026 14:48 Last: 27.05.2026 14:48 Sources 1

About this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...

GitHub internal repositories private-code leak claim

Data Leak
H score46 First: 20.05.2026 08:08 Last: 20.05.2026 08:08 Sources 1

About this happening: GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...

Latest development: 21.05.2026 17:45

A malicious version of Nx Console 18.95.0 was uploaded to Visual Studio Marketplace and Open VSX on May 18, fetched an obfuscated payload, and harvested secrets from ~/.vault-token, /etc/vault/token, .npmrc, ghp_/gho_/ghs_ tokens, AWS metadata, and other local sources; GitHub said the poisoned VS Code extension led to unauthorized access to about 3800 internal repositories.

Timeline

  1. 04.08.2026 21:50 4 articles · 2d ago

    Open VSX evil twin extension data-harvesting campaign

    Initial Disclosure

    Between July 26 and August 1, 2026, the first detected wave of counterfeit Open VSX extensions appeared and was linked to a shared exfiltration domain. The early samples already showed the impersonation pattern that later defined the broader evil twin campaign.

    Show sources