77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed.
The so-called “evil twin” campaign was discovered by Manifold Security, which detected the extensions between July 26 and August 1, 2026. Researchers linked all 77 extensions to the same activity through a shared data-exfiltration domain, as well as code and network behavior.
While 58 extensions sent only a small amount of system information, the remaining 19 contained more extensive reconnaissance that exfiltrated developer, Git repository, and continuous integration (CI) metadata.
