Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Article summary
Quick briefing — cleaned from the original RSS feed
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
1Key Takeaways
- A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.
- The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security.
- The packages have been removed from Open VSX as of.
2AIWedia Score
8.3/10
High relevance — worth your attention today
Based on source trust, recency, category impact, and story depth.
3Why it matters
Developer tooling news affects CI/CD, observability, and how AI ships in production. The Hacker News reports that a cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.
Explore related
Browse toolsDeveloper Tools news
Explore curated developer tools tools on AIWedia — compare, rank, and launch from our directory.
Full story on The Hacker News
Read full articleHeadlines aggregated via RSS for discovery on AIWedia. Original content © The Hacker News. We link to the source and do not republish full articles.