Find notable cyber news and cases, enriched with sources, timelines, and signals.

Open VSX evil twin extension data-harvesting campaign

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The Open VSX marketplace hosted 77 counterfeit extensions in an evil twin campaign that impersonated legitimate developer tools and sent environment data to an attacker-controlled server. The operation mattered because the packages harvested host, workspace, Git, and CI metadata from developer systems at scale, with 19 extensions collecting deeper reconnaissance. Researchers tied the packages together through shared infrastructure and behavior, and the counterfeit listings were later removed from the marketplace.

Related Happenings

StegoAd malicious Edge extension operation

Malware Activity
H score19 First: 29.06.2026 11:32 Last: 29.06.2026 11:32 Sources 1

About this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...

GlassWorm supply-chain malware activity

Malware Activity
H score22 First: 27.05.2026 14:48 Last: 27.05.2026 14:48 Sources 1

About this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...

GitHub internal repositories private-code leak claim

Data Leak
H score46 First: 20.05.2026 08:08 Last: 20.05.2026 08:08 Sources 1

About this happening: GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...

Latest development: 21.05.2026 17:45

A malicious version of Nx Console 18.95.0 was uploaded to Visual Studio Marketplace and Open VSX on May 18, fetched an obfuscated payload, and harvested secrets from ~/.vault-token, /etc/vault/token, .npmrc, ghp_/gho_/ghs_ tokens, AWS metadata, and other local sources; GitHub said the poisoned VS Code extension led to unauthorized access to about 3800 internal repositories.

GlassWorm OpenVSX sleeper extension campaign

Campaign
H score45 First: 28.04.2026 00:41 Last: 28.04.2026 00:41 Sources 1

About this happening: The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...

GlassWorm v2 cloned VS Code extension loaders

Malware Activity
H score30 First: 27.04.2026 14:23 Last: 27.04.2026 14:23 Sources 1

About this happening: The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...

Timeline

  1. 04.08.2026 21:50 2 articles · 1h ago

    Open VSX evil twin extension data-harvesting campaign

    Initial Disclosure

    Between July 26 and August 1, 2026, the first detected wave of counterfeit Open VSX extensions appeared and was linked to a shared exfiltration domain. The early samples already showed the impersonation pattern that later defined the broader evil twin campaign.

    Show sources