77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
Overview
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.
The 77 counterfeit extensions
Seventy-seven counterfeit extensions appeared on Open VSX between July 26 and Aug. 1, impersonating legitimate Visual Studio Code Marketplace tools while sending data to the same newly registered domain. Nineteen collected detailed information about developer machines, Git repositories, and CI/CD environments.
The extensions had been removed from Open VSX by Aug. 3, but copies already installed on developer machines or baked into development images can remain, while workspace configurations may continue to reference the affected package names. Automated provisioning increases the risk because Open VSX and Microsoftβs marketplace maintain separate publisher-ownership systems.
Investigation findings
Manifold Securityβs Aug. 4 investigation found that all 77 reused the identities and listing copy of legitimate VS Code Marketplace extensions while being distributed by accounts unaffiliated with the original publishers. Most used version 0.0.1, and all communicated with infrastructure under mangorbit[.]com.
- Fifty-eight extensions sent relatively limited information, such as a hostname and, in some cases, the workspace folder or editor version.
- The other 19 collected OS
Comments
No comments yet. Start the discussion.