Threat Intelligence

77 Fake Extensions Caught Stealing Developer Data from Open VSX Marketplace

The Hacker News · 5 Aug 2026
Key Takeaway Before installing any code editor extension, verify the publisher's authenticity, check download counts and reviews, and remove any extensions you no longer actively use.

A batch of 77 malicious extensions has been removed from the Open VSX marketplace after researchers discovered they were impersonating popular, trusted developer tools. These 'evil twin' extensions looked legitimate but were secretly designed to collect and send information about the systems and development environments they were installed on.

According to security firm Manifold Security, the fraudulent packages were uploaded to the repository over a short window between late July and early August 2026. Open VSX, an open-source alternative to Microsoft's Visual Studio Code marketplace, is widely used by developers to extend the functionality of their coding tools. Because extensions often run with significant access to a developer's machine, malicious versions can pose serious risks—including exposure of source code, credentials, and internal network details.

While the extensions have now been taken down, this incident highlights a growing trend of attackers targeting software supply chains through trusted developer ecosystems. Small businesses that rely on custom software development, even through freelancers or small technical teams, should be aware that these attacks can quietly compromise systems long before any obvious signs of trouble appear.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.