HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

77 Malicious Open VSX Extensions Harvest Developer Environment Data via ‘Evil Twin’ Campaign

Seventy‑seven counterfeit extensions on the Open VSX marketplace impersonated legitimate developer tools and exfiltrated system, IDE, and CI metadata. The breach highlights the need for SOC 2 vendor‑risk controls and continuous monitoring of third‑party code.

LiveThreat™ Intelligence · 📅 August 05, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

77 Malicious Open VSX Extensions Harvest Developer Environment Data via ‘Evil Twin’ Campaign

What Happened — 77 extensions published to the Open VSX marketplace impersonated legitimate developer tools and silently transmitted system, IDE, and CI metadata to a malicious domain. The “evil twin” packages reused names and descriptions of popular extensions, but replaced functionality with data‑exfiltration code.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a supply‑chain breach that SOC 2 vendor‑management controls are designed to detect, monitor, and evidence.
  • Continuous monitoring of third‑party components provides audit‑ready proof that only vetted extensions are in use, satisfying the CC6.1 (Vendor Management) and CC7.1 (Change Management) criteria.
  • Mapping this event to your vendor‑risk program helps maintain a defensible audit trail and demonstrates due‑diligence to regulators and customers.

Who Is Affected — Software development teams, CI/CD platforms, and organizations that rely on VS Code extensions across technology, SaaS, and cloud‑native sectors.

Recommended Actions

  • Inventory all installed VS Code extensions and cross‑reference against an approved vendor list.
  • Enforce SOC 2‑aligned vendor‑risk policies: require provenance verification, digital signatures, and continuous monitoring of third‑party packages.
  • Collect evidence of extension provenance and monitoring logs to satisfy audit requirements. Source: https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/

Technical Notes — The malicious packages used low version numbers (0.0.1), communicated with the domain mangorbit.com via HTTP(S), and exfiltrated hostnames, editor versions, CI metadata, and workspace paths. No source code, credentials, or tokens were accessed. Source: https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/

📰 Original Source
https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →