Our takeManifold Security caught 77 malicious Open VSX extensions that impersonated legitimate tools and phoned home with dev environment data. Open VSX has removed them; audit and remove any you installed between late July and early August.Cyber Resilience desk
Sources (2)
- bleeping · bleeping
- hackernews · hackernews
What this means for you — Security leader:Audit VS Code and Theia-based IDE extensions from Open VSX; remove any that were published July 26–August 1 2026 and monitor for unexpected outbound connections from developer workstations.
What this means for you — Lean IT orgs:Check the extensions installed in your team's VS Code. Remove anything added in the last two weeks that looks like a popular tool but came from Open VSX, and avoid installing new ones from there until the dust settles.
What this means for you — MSP:Scan all managed endpoints for Open VSX extensions published between July 26 and August 1 2026; uninstall the 77 identified malicious packages and advise clients to use only trusted sources for IDE extensions.
What this means for you — Researcher:Review extension source and network telemetry for any Open VSX packages installed in your dev environments in the past week.