77 Malicious Open VSX Extensions Harvest Developer Environment Data via ‘Evil Twin’ Campaign
What Happened — 77 extensions published to the Open VSX marketplace impersonated legitimate developer tools and silently transmitted system, IDE, and CI metadata to a malicious domain. The “evil twin” packages reused names and descriptions of popular extensions, but replaced functionality with data‑exfiltration code.
Why It Matters for Compliance & Audit Readiness —
- The incident exemplifies a supply‑chain breach that SOC 2 vendor‑management controls are designed to detect, monitor, and evidence.
- Continuous monitoring of third‑party components provides audit‑ready proof that only vetted extensions are in use, satisfying the CC6.1 (Vendor Management) and CC7.1 (Change Management) criteria.
- Mapping this event to your vendor‑risk program helps maintain a defensible audit trail and demonstrates due‑diligence to regulators and customers.
Who Is Affected — Software development teams, CI/CD platforms, and organizations that rely on VS Code extensions across technology, SaaS, and cloud‑native sectors.
Recommended Actions —
- Inventory all installed VS Code extensions and cross‑reference against an approved vendor list.
- Enforce SOC 2‑aligned vendor‑risk policies: require provenance verification, digital signatures, and continuous monitoring of third‑party packages.
- Collect evidence of extension provenance and monitoring logs to satisfy audit requirements. Source: https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/
Technical Notes — The malicious packages used low version numbers (0.0.1), communicated with the domain mangorbit.com via HTTP(S), and exfiltrated hostnames, editor versions, CI metadata, and workspace paths. No source code, credentials, or tokens were accessed. Source: https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/