Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
- Posted on August 5, 2026
- By The Hacker News
- 1 Views
- 1 min read
A significant security threat has emerged in the Visual Studio Code extension ecosystem as Open VSX marketplace successfully identified and removed 77 deceptive extensions designed to steal sensitive developer information. These malicious packages mimicked legitimate development tools while secretly capturing system host data, workspace configurations, Git credentials, and continuous integration credentials. This incident highlights the growing risks of supply chain attacks targeting developers through compromised extensions and underscores the critical importance of verifying extension authenticity before installation.
Summary auto-generated by AI from the original publisher's content. Editorial standards.