Open VSX evil twin extension data-harvesting campaign
Campaign
Summary
Hide ▲
Show ▼
Open VSX hosted an evil twin campaign that used 77 counterfeit extensions to impersonate legitimate developer tools and transmit host and workspace data to mangorbit[.]com. The extensions were uploaded between July 26 and August 1, 2026 and removed from the marketplace on August 3, 2026. Researchers said 58 packages mainly sent host-level data, while 19 collected deeper Git and CI metadata from developer environments. The operation reused real extension names, namespaces, and descriptions, and some packages also reported workspace and editor details before exfiltration.
Related Happenings
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
JetBrains Marketplace malicious plugin API-key theft campaign
Campaign
H score15
First: 17.06.2026 00:54
Last: 17.06.2026 00:54
Sources 1
About this happening:
A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...
JetBrains Marketplace malicious plugin API-key theft campaign
CampaignAbout this happening: A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...
Miasma software supply chain campaign expands to new PyPI wave
Campaign
H score29
First: 09.06.2026 19:34
Last: 09.06.2026 19:34
Sources 1
About this happening:
The Miasma supply-chain campaign has expanded into a new PyPI wave, increasing the risk that developers and downstream users will ingest information-stealing malware t...
Miasma software supply chain campaign expands to new PyPI wave
CampaignAbout this happening: The Miasma supply-chain campaign has expanded into a new PyPI wave, increasing the risk that developers and downstream users will ingest information-stealing malware t...
GlassWorm supply-chain malware activity
Malware Activity
H score22
First: 27.05.2026 14:48
Last: 27.05.2026 14:48
Sources 1
About this happening:
The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
GlassWorm supply-chain malware activity
Malware ActivityAbout this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
GitHub internal repositories private-code leak claim
Data Leak
H score46
First: 20.05.2026 08:08
Last: 20.05.2026 08:08
Sources 1
About this happening:
GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...
GitHub internal repositories private-code leak claim
Data LeakAbout this happening: GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...
Latest development: 21.05.2026 17:45
A malicious version of Nx Console 18.95.0 was uploaded to Visual Studio Marketplace and Open VSX on May 18, fetched an obfuscated payload, and harvested secrets from ~/.vault-token, /etc/vault/token, .npmrc, ghp_/gho_/ghs_ tokens, AWS metadata, and other local sources; GitHub said the poisoned VS Code extension led to unauthorized access to about 3800 internal repositories.
Timeline
-
04.08.2026 21:50 4 articles · 2d ago
Open VSX evil twin extension data-harvesting campaign
Initial DisclosureBetween July 26 and August 1, 2026, the first detected wave of counterfeit Open VSX extensions appeared and was linked to a shared exfiltration domain. The early samples already showed the impersonation pattern that later defined the broader evil twin campaign.
Show sources
- 77 Open VSX extensions found harvesting developer info — www.bleepingcomputer.com — 04.08.2026 21:50
- 77 Open VSX extensions found harvesting developer info — www.bleepingcomputer.com — 04.08.2026 21:50
- Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data — thehackernews.com — 05.08.2026 12:23
- Fake Open VSX Extensions Harvest Private Repo and CI Data — www.infosecurity-magazine.com — 05.08.2026 18:30