INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Data
| 2026-08-05 09:23 LOW HIGH DATA BREACH
Executive Summary
AI-generated
A cluster of 77 malicious extensions on the Open VSX marketplace, uploaded between July 26 and August 1, 2026, has been found to impersonate legitimate developer tools while transmitting information about systems and development environments. The attackers are believed to be behind these malicious extensions, which were removed from Open VSX as of August 3, 2026. These affected approximately 77 developers who installed the malicious extensions on their systems. The attack works by displaying a status bar item with a message stating they are active before firing data exfiltration steps, sending information to "[IOC HIDDEN • LOGIN REQUIRED]". As of now, these malicious extensions have been removed from Open VSX and no further updates or incidents have been reported regarding this incident.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ua•••••.dsdl
ar•••••.artsy
os•••••.sfmc
ob•••••.oscript
ex•••••.json
ex•••••.js
de•••••.json
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Mini Shai-HuludMini Shai-HuludShai-HuludShai-Hulud
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
July 15, 2026
Threat actors used a Mini Shai-Hulud variant delivered through an obfuscated Bun-based JavaScript payload to target Visual Studio Code repositories, exfiltrating developer data.
Click on any entity below to view its context and source!
infrastructure
Visual Studio Code
"
"The malware can also use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating an additional developer-to-developer infection path.
August 3, 2026
Threat actors reused real Microsoft VS Code Marketplace extension names and descriptions to publish malicious Evil Twin extensions with low version numbers, exfiltrating developer data through a shared domain.
Click on any entity below to view its context and source!
infrastructure
Vs Code
What's notable about the campaign is that it reuses the names, namespaces, and descriptions of real Microsoft VS Code Marketplace extensions, but they are published through unrelated accounts and assigned a low version number (e.g., 0.0.1).
infrastructure
0.0.1
What's notable about the campaign is that it reuses the names, namespaces, and descriptions of real Microsoft VS Code Marketplace extensions, but they are published through unrelated accounts and assigned a low version number (e.g., 0.0.1).
2026/08/05
A cluster of 77 malicious extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about installed systems and development environments.
Click on any entity below to view its context and source!
infrastructure
60 installed extension IDs
Enumerate up to 60 installed extension IDs and pick up the proxy hostname from the environment
Extract the names of any CI markers present, and separately the values of GITHUB_REPOSITORY, CI_PROJECT_PATH, the Azure DevOps collection URI, the Buil…
data_breach
77 Extensions Exfiltrating Developer Data
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data.
Tactical Metrics
Metrics
infrastructure
60
Installed Extension Ids
Click for context!
Enumerate up to 60 installed extension IDs and pick up the proxy hostname from the environment
Extract the names of any CI markers present, and separately the values of GITHUB_REPOSITORY, CI_PROJECT_PATH, the Azure DevOps collection URI, the Buil…
Metrics
infrastructure
Vs Code
Affected Product
What's notable about the campaign is that it reuses the names, namespaces, and descriptions of real Microsoft VS Code Marketplace extensions, but they are published through unrelated accounts and assigned a low version number (e.g., 0.0.1).
Metrics
infrastructure
0.0.1
Software Version
What's notable about the campaign is that it reuses the names, namespaces, and descriptions of real Microsoft VS Code Marketplace extensions, but they are published through unrelated accounts and assigned a low version number (e.g., 0.0.1).
Metrics
infrastructure
Visual Studio Code
Affected Product
"
"The malware can also use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating an additional developer-to-developer infection path.
Metrics
data_breach
77
Extensions Exfiltrating Developer Data
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data.
Intelligence Sources
The Hacker News
2026-08-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T10:48
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Codespace
entity
5x
timeline
Temporal Reference
August 1, 2026
date
3x
tactic
Cyber Operation Type
Impersonate
tactic
3x
general metric
Extensions
77
extensions
2x
infrastructure
Affected Product
Vs Code
software
2x
tactic
MITRE ATT&CK Technique
T1557.004 - Evil Twin
technique
2x
malware
Malware Payload
Mini Shai-Hulud
tool
Contextual Telemetry
Context Block
5 METRICS
infrastructure
Installed Extension Ids
60
installed extension ids
infrastructure
Software Version
0.0.1
version
data breach
Extensions Exfiltrating Developer Data
77
extensions exfiltrating developer data
general metric
Unique Npm Packages
450
unique npm packages
general metric
Artifacts
2,244
artifacts
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.