Tuttiquotidiani is completely free. Every day we aggregate news from 100+ sources and generate original AI summaries for you. Help us keep the service running with a small donation, or become TQ Pro for just €1/month.

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

  • Posted on August 5, 2026
  • By The Hacker News
  • 1 Views
  • 1 min read
In brief

A significant security threat has emerged in the Visual Studio Code extension ecosystem as Open VSX marketplace successfully identified and removed 77 deceptive extensions designed to steal sensitive developer information. These malicious packages mimicked legitimate development tools while secretly capturing system host data, workspace configurations, Git credentials, and continuous integration credentials. This incident highlights the growing risks of supply chain attacks targeting developers through compromised extensions and underscores the critical importance of verifying extension authenticity before installation.

Summary auto-generated by AI from the original publisher's content. Editorial standards.

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
continue reading...

Author
The Hacker News

You May Also Like