77 Open VSX extensions impersonated legitimate developer tools in an “evil twin” campaign and sent system and development-environment data to attacker infrastructure. Manifold Security linked the packages to mangorbit[.]com and found that 19 of them collected unusually detailed reconnaissance, including Git and CI metadata. #OpenVSX #ManifoldSecurity #mangorbit
Keypoints
- Seventy-seven fake extensions copied real Open VSX packages.
- Manifold Security detected the campaign between July 26 and August 1, 2026.
- All samples used mangorbit[.]com and related subdomains for data exfiltration.
- Nineteen extensions collected detailed Git, CI, and workspace metadata.
- The packages were removed from Open VSX, but manual cleanup may still be needed.