Researchers uncovered a campaign of 77 malicious "evil twin" extensions on the Open VSX marketplace that impersonated legitimate developer tools and quietly exfiltrated host and development-environment metadata. Manifold Security linked the packages through shared code, behavior, and communications with mangorbit[.]com, finding that 58 extensions gathered basic system details while 19 conducted broader reconnaissance. Open VSX removed the packages by August 3 after the activity was identified between July 26 and August 1.
The more invasive extensions collected information including Git metadata, workspace paths, installed extensions, and identifiers tied to CI and cloud development environments, giving attackers enough data to profile developers, organizations, and potentially private repositories. Researchers said the campaign did not access source code, credentials, authentication tokens, SSH keys, or browser data, but warned that affected users still need to manually uninstall the extensions from their systems and block the campaign domain to prevent further data collection.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
On August 4, 2026, Ax Sharma and Cody Nash of Manifold Security published research documenting the 77 counterfeit Open VSX extensions, their impersonation of legitimate VS Code Marketplace listings, and their data-exfiltration behavior tied to mangorbit.com.
Open VSX had removed the 77 malicious extensions by August 3, 2026. Affected users still needed to manually remove installed extensions and block the campaign domain.
Between August 16 and August 20, 2026, Open VSX removed three extension IDs from its malicious-extension list after legitimate maintainers proved ownership of projects previously impersonated in the 77-extension campaign. The change allowed legitimate publishers to reclaim and, in two cases, republish extensions under identifiers that had earlier been used by malware.
The exfiltration domain mangorbit[.]com used by the malicious Open VSX extensions was registered eleven days before the first packages appeared. Manifold linked all 77 extensions to infrastructure under this domain.
Between July 26 and August 1, 2026, Manifold Security discovered 77 malicious extensions on the Open VSX marketplace. The packages were linked through shared code, behavior, and mangorbit[.]com infrastructure.
Analysis by Ax Sharma and Cody Nash found that 19 of the 77 malicious Open VSX extensions gathered extensive Git, CI, installed-extension, proxy, and telemetry-setting data. These variants also used staged retry logic for up to seven days and could fetch an alternate exfiltration URL via DNS TXT records if the primary domain was blocked.
The first malicious Open VSX packages in the "evil twin" campaign appeared after the mangorbit[.]com domain was registered. The extensions impersonated legitimate developer tools and were published from unrelated accounts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
10 references tracked. Mallory keeps watching after this page renders.
socket.dev
Open sourcetechrepublic.com
Open sourcexakep.ru
Open sourcecyberveille.ch
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcemanifold.security
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.