Threats · 54 days ago
The break is not the 77 removals. It is that lookalike extensions in a real marketplace can quietly turn normal installs into mapping of developer hosts, repos, and CI context. That means the development environment is the target, not the extension listing.
Open VSX removed a cluster of 77 extensions uploaded between July 26 and August 1 that copied real tool names, namespaces, and descriptions. Fifty-eight sent lightweight metadata such as hostname or workspace name, and 19 sent fuller details including the open repository, CI system, editor version, OS username, and workspace path.
The risk is broader than one bad plugin. Small bits of telemetry from many developer machines can still reveal which repositories matter and which CI environments are worth hitting next.
2 sources covering this story
Fake Open VSX Extensions Harvest Private Repo and CI Data
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
Part of the PlainSec briefing for 2026-08-05