77 Open VSX extensions found harvesting developer info
77 Open VSX extensions were found to be harvesting developer information, including system details and development environment metadata. The extensions, which were discovered by Manifold Security, did not access source code or credentials but did collect information that …
Intelligence analysis by Llama

A recent campaign involving 77 Open VSX extensions has been discovered to be collecting developer information, including system details and development environment metadata. The extensions, which were designed to impersonate legitimate developer tools, were found to be transmitting information about the systems and development environments where they were installed.
Imagine you're working on a project and you install a tool to help you. But what if that tool was actually collecting information about your computer and your project without you knowing? That's what happened with 77 Open VSX extensions that were found to be collecting developer information. These extensions were designed to look like real tools, but they were actually sending information to a server without the user's knowledge or consent.
Analysis
A $60B Vote of Confidence
The discovery of 77 malicious Open VSX extensions has sent shockwaves through the development community. These extensions, which were designed to impersonate legitimate developer tools, were found to be collecting developer information, including system details and development environment metadata. The extensions, which were discovered by Manifold Security, did not access source code or credentials but did collect information that could expose private repository names or paths.
The campaign, which was active between July 26 and August 1, 2026, used a shared data-exfiltration domain and code and network behavior to link all 77 extensions to the same activity. While 58 extensions sent only a small amount of system information, the remaining 19 contained more extensive reconnaissance that exfiltrated developer, Git repository, and continuous integration (CI) metadata.
What is unusual about this campaign is that the Open VSX listings disclosed that they collected what they called 'anonymous usage metrics' and accurately said they did not access source code or credentials. However, Manifold reports that the extensions sent more data than disclosed, including CI information that could expose private repository names or paths.
The packages were removed from Open VSX by August 3, 2026, but the packages would still need to be manually removed from developers' systems and applications. Manifold recommends checking systems and workspace configuration files for extension IDs listed in its report and blocking the mangorbit[.]com domain, which is used by all 77 packages in the campaign.
Why Cursor?
The discovery of these malicious extensions serves as a reminder to developers to regularly check their systems and workspace configuration files for potential security threats. It also highlights the importance of being cautious when installing extensions on development platforms.
The Road Ahead
In the wake of this discovery, developers should take steps to ensure their systems and applications are secure. This includes regularly checking for updates and patches, as well as being cautious when installing new extensions. By taking these steps, developers can help prevent similar security threats in the future.
Key points
- 77 Open VSX extensions were found to be harvesting developer information, including system details and development environment metadata.
- The extensions did not access source code or credentials but did collect information that could expose private repository names or paths.
- The campaign was active between July 26 and August 1, 2026, and used a shared data-exfiltration domain and code and network behavior to link all 77 extensions to the same activity.
- The packages were removed from Open VSX by August 3, 2026, but the packages would still need to be manually removed from developers' systems and applications.
In the wake of this discovery, developers can take steps to ensure their systems and applications are secure. This includes regularly checking for updates and patches, as well as being cautious when installing new extensions. By taking these steps, developers can help prevent similar security threats in the future.
The discovery of these malicious extensions highlights the importance of being cautious when installing extensions on development platforms. If developers are not careful, they may inadvertently install malicious extensions that can compromise their systems and applications.



