Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Extensions Removed from Open VSX Marketplace

Malicious Extensions Removed from Open VSX Marketplace

Posted on August 5, 2026 By CWS

In a significant security update, Open VSX has removed 77 extensions that were discovered to be impersonating genuine developer tools while secretly transmitting sensitive information about the systems they were installed on. Known as ‘evil twin’ extensions, these packages were identified and eliminated following an analysis by Manifold Security. The malicious extensions were initially uploaded to the Open VSX repository between July 26 and August 1, 2026, and were taken down by August 3, 2026.

Details of the Malicious Activity

According to security researchers Ax Sharma and Cody Nash, most of these extensions relayed minimal data such as the hostname of the machine. However, 19 of them sent extensive details including the machine’s description, the active repository in the editor, and the continuous integration (CI) environment the editor was operating within. A total of 58 of these extensions were identified as lightweight tools designed to extract basic information like the hostname and, occasionally, the workspace folder name or editor version.

These extensions shared a common data-exfiltration domain and exhibited similar code and behavioral patterns. The extensions masqueraded under names and descriptions of legitimate Open VSX tools, but were distributed through unrelated accounts at low version numbers, typically 0.0.1. The core alteration in these malicious extensions was the substitution of the contents of the bundled ‘extension.js’ file, enabling the capture and transmission of data under the guise of ‘anonymous usage metrics.’

Targeted Data and Transmission Methods

The remaining extensions in the group served as reconnaissance payloads, transmitting intricate developer-related information. This included the local hostname and OS username, editor name and version, and more. Notably, all data was directed to the domain ‘mangorbit[.]com,’ registered just days before the first appearance of these extensions. This exfiltration method was coupled with further intrusive actions, such as inspecting files within the ‘.git’ directory to gather details about Git remote hosts, the developer’s email domain, and CI environment variables.

These reconnaissance extensions also featured a fallback mechanism, querying a DNS TXT record to retrieve an alternative exfiltration URL should the primary domain become inaccessible. The persistence of these attacks was evident, as attempts to collect data were scheduled to retry at intervals, continuing for up to a week if initial requests went unanswered.

Broader Implications and Future Security Measures

This incident is part of a wider pattern of software supply chain attacks. Notably, 450 npm packages spanning over 2,000 artifacts were recently compromised, distributing an information-stealing malware dubbed ‘ChainDrop.’ The malicious packages exploit stolen npm tokens to propagate trojanized versions containing a credential-stealing worm. Microsoft has linked these activities to a variant of the Shai-Hulud npm worm, which employs advanced techniques not previously documented.

Security experts, including OX Security, emphasize the necessity for enhanced security measures to counter these supply chain threats. Recommendations include implementing granular permission controls and requiring explicit permissions before packages can access sensitive credentials. As the landscape of digital threats evolves, such measures are crucial for safeguarding developer environments against sophisticated attacks.

The Hacker News Tags:CI systems, data exfiltration, developer security, evil twin extensions, malicious extensions, Manifold Security, npm packages, Open VSX, Software Security, supply chain attack

Post navigation

Previous Post: 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen
Next Post: CISA Alerts on Langflow, N-central, and Tomcat Risks

Related Posts

Anthropic’s AI Models Breach Security in Tests Anthropic’s AI Models Breach Security in Tests The Hacker News
Checkmarx Data Breach: GitHub Data Exposed on Dark Web Checkmarx Data Breach: GitHub Data Exposed on Dark Web The Hacker News
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto The Hacker News
Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale The Hacker News
Operation PowerOFF Disrupts Major DDoS Networks Operation PowerOFF Disrupts Major DDoS Networks The Hacker News
Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Reports Active Exploitation of Key Software Flaws
  • Rapid Response: Microsoft Defender Thwarts Ransomware in Seconds
  • CISA Alerts on Langflow, N-central, and Tomcat Risks
  • Malicious Extensions Removed from Open VSX Marketplace
  • 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Reports Active Exploitation of Key Software Flaws
  • Rapid Response: Microsoft Defender Thwarts Ransomware in Seconds
  • CISA Alerts on Langflow, N-central, and Tomcat Risks
  • Malicious Extensions Removed from Open VSX Marketplace
  • 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark