Executive Summary
Between July 26 and August 1, 2026, Manifold Security identified 77 malicious extensions on the Open VSX marketplace that impersonated legitimate developer tools. These 'evil twin' extensions collected and transmitted system and development environment data to a server at mangorbit[.]com. While 58 extensions sent minimal system information, 19 conducted extensive reconnaissance, exfiltrating metadata related to developers, Git repositories, and continuous integration environments. Notably, these extensions did not access source code, credentials, authentication tokens, SSH material, or browser data. The malicious packages were removed from Open VSX by August 3, 2026, but developers are advised to manually remove them from their systems. This incident underscores the growing threat of supply chain attacks targeting developer environments. The use of counterfeit extensions to harvest sensitive metadata highlights the need for enhanced vigilance and security measures when sourcing and installing development tools.
Why This Matters Now
The incident highlights the increasing sophistication of supply chain attacks targeting developer environments, emphasizing the urgent need for enhanced vigilance and security measures when sourcing and installing development tools.
Attack Path Analysis
Attackers introduced malicious 'evil twin' extensions into the Open VSX marketplace, leading to unauthorized data exfiltration from compromised developer environments.
Kill Chain Progression
Initial Compromise
Description
Attackers published counterfeit extensions on the Open VSX marketplace, impersonating legitimate tools to deceive developers into installation.
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
Application Layer Protocol: Web Protocols
System Information Discovery
System Owner/User Discovery
Remote System Discovery
System Network Connections Discovery
Data from Local System
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure the integrity of software and scripts
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Supply Chain Security
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply-chain attacks targeting developer extensions create critical risks for software development environments, compromising CI/CD pipelines and exposing private repository metadata.
Information Technology/IT
Evil twin VSX extensions harvesting developer information threaten IT infrastructure security through compromised development tools and unauthorized system reconnaissance capabilities.
Computer/Network Security
Malicious extensions targeting security development teams pose significant risks by exposing security tool configurations, threat detection capabilities, and organizational security postures.
Financial Services
Developer-focused supply-chain attacks threaten financial software integrity, potentially exposing sensitive application architectures and compliance-regulated development environments to unauthorized reconnaissance.
Sources
- 77 Open VSX extensions found harvesting developer infohttps://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/Verified
- 77 "evil twin" Open VSX extensions: 19 copy private repo and CI data to a new domainhttps://www.manifold.security/blog/open-vsx-evil-twin-extensionsVerified
- GlassWorm Abuses 72 Open VSX Extensions to Target Developershttps://cybersecuritywaala.com/news/glassworm-abuses-72-open/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the reach of malicious extensions by enforcing strict workload isolation, reducing the potential for unauthorized access.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the scope of privileges accessible to the malicious extensions, reducing their ability to exploit elevated permissions.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the ability of malicious extensions to move laterally by enforcing strict communication controls between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit unauthorized outbound communications by monitoring and controlling data flows across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by enforcing strict outbound traffic policies, reducing unauthorized data transfers.
The CNSF would likely reduce the overall impact by limiting the attacker's ability to access and exfiltrate sensitive data, thereby reducing the potential for organizational profiling and further exploitation.
Impact at a Glance
Affected Business Functions
- Software Development
- Continuous Integration/Continuous Deployment (CI/CD)
- Source Code Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of developer system information, Git repository metadata, and CI/CD environment details.
Recommended Actions
Key Takeaways & Next Steps
- • Implement strict validation and verification processes for third-party extensions to prevent the installation of malicious software.
- • Utilize Zero Trust Segmentation to enforce least privilege access, limiting the capabilities of extensions and reducing potential attack surfaces.
- • Enhance Multicloud Visibility & Control to monitor and analyze traffic patterns, enabling the detection of anomalous behaviors indicative of data exfiltration.
- • Apply Egress Security & Policy Enforcement to restrict unauthorized outbound communications from development environments, mitigating data leakage risks.
- • Conduct regular Threat Detection & Anomaly Response exercises to identify and respond to suspicious activities within the development pipeline promptly.



