Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 malicious extensions masquerading as legitimate developer tools on the Open VSX marketplace have been discovered. These extensions, dubbed ‘evil twins,’ exfiltrate sensitive developer data, including workspace details, editor information, and CI/CD environment details, to a single domain (mangorbit[.]com). The campaign utilizes deceptive naming and descriptions, and employs sophisticated reconnaissance techniques to identify installations and continuously collect data over extended periods, even if the initial request is blocked. This follows a larger software supply chain attack (ChainDrop) involving a similar worm, leveraging stolen npm tokens to inject malware into repositories.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
