#10
The Hacker News
general
August 05, 2026 at 09:23 UTC
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
By [email protected] (The Hacker News)
AI Summary
77 malicious 'evil twin' extensions uploaded to the Open VSX marketplace between July 26 and August 1, 2026, were found impersonating legitimate developer tools while exfiltrating system and development environment data from infected machines. Discovered by Manifold Security, the packages have since been removed, but the campaign mirrors similar supply chain attacks on VSCode marketplaces and targets software developers who represent high-value compromise targets for supply chain attacks.
Relevance score: 76.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →