Open VSX Evil Twins Turn Developer Trust into Recon

The break is not the 77 removals. It is that lookalike extensions in a real marketplace can quietly turn normal installs into mapping of developer hosts, repos, and CI context. That means the development environment is the target, not the extension listing. Open VSX removed a cluster of 77 extensions uploaded between July 26 and August 1 that copied real tool names, namespaces, and descriptions. Fifty-eight sent lightweight metadata such as hostname or workspace name, and 19 sent fuller details including the open repository, CI system, editor version, OS username, and workspace path. The risk is broader than one bad plugin. Small bits of telemetry from many developer machines can still reveal which repositories matter and which CI environments are worth hitting next.

Part of the PlainSec briefing for 2026-08-05

Every edition of this story: Open VSX Evil Twins Turn Developer Trust into Recon

Sources