Security researchers identify 77 malicious extensions distributed through the Open VSX marketplace that impersonate legitimate developer tools. According to reporting cited by multiple outlets, the extensions are designed as “evil twins,” meaning they mimic real or expected tooling while collecting and transmitting details about the devices and development environments where they are installed. Manifold Security is credited with detecting the activity, and the extensions were uploaded to the Open VSX repository over a short window from July 26 to August 1, 2026. After the findings were reported, the malicious packages are removed from Open VSX as of a subsequent date noted by the sources. The reports describe the targeted information as including system and environment data rather than normal extension functionality, indicating an exfiltration goal. The coverage does not report specific downstream impacts such as confirmed breaches of external accounts, but it characterizes the extensions’ behavior as harvesting developer information. Both outlets frame the incident as a supply-chain risk involving third-party extensions published to an open marketplace.