Cyber Resilience
← All news
Corroborated

77 Open VSX extensions found harvesting developer info

Our takeManifold Security caught 77 malicious Open VSX extensions that impersonated legitimate tools and phoned home with dev environment data. Open VSX has removed them; audit and remove any you installed between late July and early August.
Sources (2)
What this means for you — Security leader:Audit VS Code and Theia-based IDE extensions from Open VSX; remove any that were published July 26–August 1 2026 and monitor for unexpected outbound connections from developer workstations.
What this means for you — Lean IT orgs:Check the extensions installed in your team's VS Code. Remove anything added in the last two weeks that looks like a popular tool but came from Open VSX, and avoid installing new ones from there until the dust settles.
What this means for you — MSP:Scan all managed endpoints for Open VSX extensions published between July 26 and August 1 2026; uninstall the 77 identified malicious packages and advise clients to use only trusted sources for IDE extensions.
What this means for you — Researcher:Review extension source and network telemetry for any Open VSX packages installed in your dev environments in the past week.