Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data

Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk. The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic .

Security experts discovered over 150 fraudulent Open VSX extensions that impersonated legitimate Visual Studio Code Marketplace tools. Between July 26 and August 1, 77 of these counterfeit extensions targeted developer credentials, source code, and CI/CD systems. They were distributed via unauthorized accounts and exposed data to the newly registered domain mangorbit[.]com.

Nineteen of the extensions collected sensitive information including developer machine details, Git repository and CI/CD environment data. By August 3, all 77 extensions had been removed, but installations on developer machines or embedded in development images could persist. The reused identities and listing descriptions of legitimate extensions increased the risk of supply-chain attacks.

Manifold Security's investigation revealed that all 77 extensions mimicked the original publishers' details while communicating with the malicious infrastructure. No source-code, credentials, tokens, SSH-keys, or browser-data were stolen in the analyzed packages, but some extensions mistakenly claimed CI values remained on the machine.

Developers should regularly inventory installed extensions, review configuration files, and check for suspicious activity involving mangorbit[.]com to mitigate the supply-chain risk.

Written by urgent.news from TechRepublic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techrepublic.com →

More in Tech

More from Monday 10 August →