Security researchers identify 77 malicious extensions distributed through the Open VSX marketplace that impersonate legitimate developer tools. According to reporting cited by multiple outlets, the extensions are designed as “evil twins,” meaning they mimic real or expected tooling while collecting and transmitting details about the devices and development environments where they are installed. Manifold Security is credited with detecting the activity, and the extensions were uploaded to the Open VSX repository over a short window from July 26 to August 1, 2026. After the findings were reported, the malicious packages are removed from Open VSX as of a subsequent date noted by the sources. The reports describe the targeted information as including system and environment data rather than normal extension functionality, indicating an exfiltration goal. The coverage does not report specific downstream impacts such as confirmed breaches of external accounts, but it characterizes the extensions’ behavior as harvesting developer information. Both outlets frame the incident as a supply-chain risk involving third-party extensions published to an open marketplace.
77 malicious “evil twin” extensions removed from Open VSX after developer data harvesting
Security researchers identify 77 malicious extensions distributed through the Open VSX marketplace that impersonate legitimate developer tools. According to reporting cited by multiple outlets, the ex...
- Security researchers find 77 malicious “evil twin” extensions on the Open VSX marketplace.
- The extensions impersonate legitimate developer tools.
- The packages collect and transmit information about installed systems and development environments.
- The extensions are uploaded between July 26 and August 1, 2026.
- Open VSX removes the malicious extensions after detection.
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
4 hours ago77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]
19 hours ago
UK-based Nigerian woman rejects £15m offer to return home after losing two children
A Nigerian woman living in the United Kingdom says she will not return to Nigeria even if offered £15 million, after los...
Huawei nova 16 SE launches with Kirin 8020, 8,500mAh battery and 6.84-inch display
Huawei officially unveils the nova 16 SE in China, following earlier reports of its design and specifications. The hands...
Developers describe workflows using Claude Code and AI agents with deterministic checks
Multiple Dev.to articles and a UX Collective piece describe how developers adapt AI coding tools (especially Claude Code...