Open VSX evil twin extension data-harvesting campaign
Campaign
Summary
Hide ▲
Show ▼
The Open VSX marketplace hosted 77 counterfeit extensions in an evil twin campaign that impersonated legitimate developer tools and sent environment data to an attacker-controlled server. The operation mattered because the packages harvested host, workspace, Git, and CI metadata from developer systems at scale, with 19 extensions collecting deeper reconnaissance. Researchers tied the packages together through shared infrastructure and behavior, and the counterfeit listings were later removed from the marketplace.
Related Happenings
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
GlassWorm supply-chain malware activity
Malware Activity
H score22
First: 27.05.2026 14:48
Last: 27.05.2026 14:48
Sources 1
About this happening:
The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
GlassWorm supply-chain malware activity
Malware ActivityAbout this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
GitHub internal repositories private-code leak claim
Data Leak
H score46
First: 20.05.2026 08:08
Last: 20.05.2026 08:08
Sources 1
About this happening:
GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...
GitHub internal repositories private-code leak claim
Data LeakAbout this happening: GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...
Latest development: 21.05.2026 17:45
A malicious version of Nx Console 18.95.0 was uploaded to Visual Studio Marketplace and Open VSX on May 18, fetched an obfuscated payload, and harvested secrets from ~/.vault-token, /etc/vault/token, .npmrc, ghp_/gho_/ghs_ tokens, AWS metadata, and other local sources; GitHub said the poisoned VS Code extension led to unauthorized access to about 3800 internal repositories.
GlassWorm OpenVSX sleeper extension campaign
Campaign
H score45
First: 28.04.2026 00:41
Last: 28.04.2026 00:41
Sources 1
About this happening:
The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
GlassWorm OpenVSX sleeper extension campaign
CampaignAbout this happening: The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
GlassWorm v2 cloned VS Code extension loaders
Malware Activity
H score30
First: 27.04.2026 14:23
Last: 27.04.2026 14:23
Sources 1
About this happening:
The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
GlassWorm v2 cloned VS Code extension loaders
Malware ActivityAbout this happening: The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
Timeline
-
04.08.2026 21:50 2 articles · 1h ago
Open VSX evil twin extension data-harvesting campaign
Initial DisclosureBetween July 26 and August 1, 2026, the first detected wave of counterfeit Open VSX extensions appeared and was linked to a shared exfiltration domain. The early samples already showed the impersonation pattern that later defined the broader evil twin campaign.
Show sources
- 77 Open VSX extensions found harvesting developer info — www.bleepingcomputer.com — 04.08.2026 21:50
- 77 Open VSX extensions found harvesting developer info — www.bleepingcomputer.com — 04.08.2026 21:50