Return to Threats

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

thehackernews.com 2026-08-05 AI supply chain High

What Happened

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of

Why It Matters

The report describes a campaign where 77 malicious "evil twin" extensions on the Open VSX marketplace impersonated legitimate developer tools and exfiltrated machine, workspace, Git, and CI metadata to a single domain, mangorbit[.]com.[1][2][3] According to Manifold Security, these counterfeit extensions were uploaded between July 26 and August 1, 2026 and removed from Open VSX by August 3, but they remain on any systems where they were installed.[2][3][6] From a RealGround perspective, this is a clear developer toolchain and AI supply chain risk: compromised extensions in editors and CI pipelines that support AI coding assistants or agent workflows can leak repository and environment context, undermining data governance and contaminating AI-assisted development. Organizations should treat extension marketplaces as critical supply chain dependencies, enforce strict publisher verification and SBOM-based extension allowlisting, and consider continuous red teaming of AI-enabled development environments to detect similar telemetry or exfiltration behavior early.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html

Talk to AI CISO