Particle.news

77 Evil-Twin Extensions Removed From Open VSX After Data-Collection Campaign

Researchers warn infected developer machines will keep leaking repository and CI metadata until installed copies are removed with mangorbit[.]com blocked.

Overview

  • Manifold Security discovered 77 counterfeit extensions on Open VSX that copied real extension names and replaced their code to collect and send environment data to mangorbit[.]com.
  • Fifty-eight packages sent only basic host identifiers while nineteen carried reconnaissance logic that read .git folders, enumerated installed extensions, and captured CI and cloud development identifiers.
  • All samples communicated with infrastructure tied to mangorbit[.]com and its subdomains and some variants used retry logic and DNS TXT fallbacks to ensure data delivery.
  • The 77 malicious packages were removed from Open VSX on Monday, August 3, 2026, but researchers say each infected editor must be manually uninstalled to stop ongoing exfiltration.
  • Security teams are advised to check reported extension IDs, block mangorbit[.]com, pin trusted publishers in mirrored registries, and treat unverified-publisher installs as a high-risk event because of broader 2026 supply-chain trends.