discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

77 Open VSX extensions found harvesting developer info

77 Open VSX extensions were found to be harvesting developer information, including system details and development environment metadata. The extensions, which were discovered by Manifold Security, did not access source code or credentials but did collect information that …

By Lawrence Abrams·Aug 4·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

77 Open VSX extensions found harvesting developer info
Image: bleepingcomputer.com

A recent campaign involving 77 Open VSX extensions has been discovered to be collecting developer information, including system details and development environment metadata. The extensions, which were designed to impersonate legitimate developer tools, were found to be transmitting information about the systems and development environments where they were installed.

Why it matters

This story matters because it highlights the importance of being cautious when installing extensions on development platforms. The discovery of these malicious extensions serves as a reminder to developers to regularly check their systems and workspace configuration files for potential security threats.

Imagine you're working on a project and you install a tool to help you. But what if that tool was actually collecting information about your computer and your project without you knowing? That's what happened with 77 Open VSX extensions that were found to be collecting developer information. These extensions were designed to look like real tools, but they were actually sending information to a server without the user's knowledge or consent.

Analysis

A $60B Vote of Confidence

The discovery of 77 malicious Open VSX extensions has sent shockwaves through the development community. These extensions, which were designed to impersonate legitimate developer tools, were found to be collecting developer information, including system details and development environment metadata. The extensions, which were discovered by Manifold Security, did not access source code or credentials but did collect information that could expose private repository names or paths.

The campaign, which was active between July 26 and August 1, 2026, used a shared data-exfiltration domain and code and network behavior to link all 77 extensions to the same activity. While 58 extensions sent only a small amount of system information, the remaining 19 contained more extensive reconnaissance that exfiltrated developer, Git repository, and continuous integration (CI) metadata.

What is unusual about this campaign is that the Open VSX listings disclosed that they collected what they called 'anonymous usage metrics' and accurately said they did not access source code or credentials. However, Manifold reports that the extensions sent more data than disclosed, including CI information that could expose private repository names or paths.

The packages were removed from Open VSX by August 3, 2026, but the packages would still need to be manually removed from developers' systems and applications. Manifold recommends checking systems and workspace configuration files for extension IDs listed in its report and blocking the mangorbit[.]com domain, which is used by all 77 packages in the campaign.

Why Cursor?

The discovery of these malicious extensions serves as a reminder to developers to regularly check their systems and workspace configuration files for potential security threats. It also highlights the importance of being cautious when installing extensions on development platforms.

The Road Ahead

In the wake of this discovery, developers should take steps to ensure their systems and applications are secure. This includes regularly checking for updates and patches, as well as being cautious when installing new extensions. By taking these steps, developers can help prevent similar security threats in the future.

Key points

  • 77 Open VSX extensions were found to be harvesting developer information, including system details and development environment metadata.
  • The extensions did not access source code or credentials but did collect information that could expose private repository names or paths.
  • The campaign was active between July 26 and August 1, 2026, and used a shared data-exfiltration domain and code and network behavior to link all 77 extensions to the same activity.
  • The packages were removed from Open VSX by August 3, 2026, but the packages would still need to be manually removed from developers' systems and applications.
The Upside

In the wake of this discovery, developers can take steps to ensure their systems and applications are secure. This includes regularly checking for updates and patches, as well as being cautious when installing new extensions. By taking these steps, developers can help prevent similar security threats in the future.

The Downside

The discovery of these malicious extensions highlights the importance of being cautious when installing extensions on development platforms. If developers are not careful, they may inadvertently install malicious extensions that can compromise their systems and applications.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityopen-vsxdeveloper-infomalicious-extensionsdata-collection

Author

Lawrence Abrams

Intelligence analysis by

Llama

Published

Aug 4, 2026

Source

bleepingcomputer.com

Share

Topics

securityopen-vsxdeveloper-infomalicious-extensionsdata-collection

Related

More from this desk

Aug 4·thehackernews.com

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness PhaaS, a commercial phishing-as-a-service toolkit, has added support for device code phishing, a rapidly growing cyber threat that bypasses Multi-Factor Authentication (MFA) and steals user tokens.

Aug 4·wired.com

Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal

The US Army is poised to sign a contract to acquire and rapidly deploy a working laser weapon, the Enduring High Energy Laser, to defend its bases from drone attacks. This will be the first time the US military has committed to equipping its forces with laser weapons in s…

Aug 4·bleepingcomputer.com

Massive ChainDrop npm supply-chain attack infects hundreds of packages

A massive supply-chain attack has compromised over 1,300 packages on the Node Package Manager (npm) registry, including popular ones like Keyv and Cacheable. The attack, named 'ChainDrop', has been linked to a self-propagating malware that steals sensitive information and…

Aug 4·bleepingcomputer.com

Varonis Agent IBAC keeps AI agents within their intended boundaries

Varonis has announced Agent Intent-Based Access Control (IBAC), a new capability in Varonis Atlas that lets businesses connect AI agents to their enterprise data with safeguards that stop dangerous or out-of-policy behavior.