[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fr_jldRW3SDUPzbY67i0zxm-vySjz5b80TKmTvZFrlX0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"b2cb143b-61a4-48c8-bc19-e316b251ee21","77-malicious-evil-twin-extensions-caught-stealing-developer-data-from-open-vsx","401cc7cb-0f3a-4ceb-8d96-b048d3ef6a0f","77 Malicious Evil Twin Extensions Caught Stealing Developer Data from Open VSX","Threat actors uploaded 77 counterfeit extensions to the Open VSX marketplace that closely mimicked legitimate developer tools, a classic software supply chain attack known as 'typosquatting' or 'evil twin' impersonation. These extensions silently exfiltrated sensitive development environment data — including hostnames, Git repository details, CI system configurations, and installed extension IDs — to an attacker-controlled domain. The attack highlights how developer tooling ecosystems are high-value targets because compromised developer machines can serve as pivot points into production systems and source code. The incident matters because many developers implicitly trust marketplace repositories, often installing extensions without rigorous vetting, creating a wide and largely unmonitored attack surface.","**Immediate actions:**\n- Audit all currently installed VS Code or Open VSX extensions against a verified allowlist and remove any unrecognized or suspicious entries.\n- Block outbound connections to known malicious domains (e.g., `mangorbit[.]com`) at the firewall or DNS filtering layer.\n- Scan developer workstations for indicators of compromise, focusing on unexpected data exfiltration or anomalous network traffic originating from editor processes.\n\n**Long-term improvements:**\n- Establish an organizational policy requiring extensions to be vetted and approved before installation on developer machines.\n- Implement a curated internal extension marketplace or allowlist that restricts developers to pre-approved, security-reviewed tools.\n- Integrate software composition analysis (SCA) tooling into CI\u002FCD pipelines to detect and flag suspicious or newly introduced dependencies and extensions.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) solutions capable of monitoring network connections spawned by IDE processes and alerting on unusual outbound traffic.\n- Enable DNS query logging and set up alerts for developer machines communicating with newly registered or uncategorized domains.\n- Periodically review extension update logs to detect silent version changes that may introduce malicious code post-installation.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 13: Network Monitoring and Defense","NIST SP 800-161: Supply Chain Risk Management Practices","NIST CSF DE.CM-3: Personnel activity is monitored","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SA-12: Supply Chain Protection","GDPR Article 32: Security of Processing (data exfiltration risk)","SLSA Supply Chain Levels for Software Artifacts (Provenance Verification)","ITIL Service Configuration Management: Approved software baseline control","published","2026-08-05T12:22:10.189732+00:00","2026-08-05T12:22:09.899+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fopen-vsx-removes-77-malicious-evil-twin.html","open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data-e7d8af","Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]