Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Read full story on The Hacker News
Share
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
AI disclosure

Summary

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.