Overview
- Manifold Security discovered 77 counterfeit extensions on Open VSX that copied real extension names and replaced their code to collect and send environment data to mangorbit[.]com.
- Fifty-eight packages sent only basic host identifiers while nineteen carried reconnaissance logic that read .git folders, enumerated installed extensions, and captured CI and cloud development identifiers.
- All samples communicated with infrastructure tied to mangorbit[.]com and its subdomains and some variants used retry logic and DNS TXT fallbacks to ensure data delivery.
- The 77 malicious packages were removed from Open VSX on Monday, August 3, 2026, but researchers say each infected editor must be manually uninstalled to stop ongoing exfiltration.
- Security teams are advised to check reported extension IDs, block mangorbit[.]com, pin trusted publishers in mirrored registries, and treat unverified-publisher installs as a high-risk event because of broader 2026 supply-chain trends.