{
  "id": 477133,
  "title": "77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data",
  "url": "https://urgent.news/2026/08/10/77-counterfeit-open-vsx-extensions-collected-developer-and-ci-cd-data",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-10T14:52:52.000Z",
  "source": {
    "name": "TechRepublic",
    "slug": "techrepublic",
    "url": "https://www.techrepublic.com/article/news-open-vsx-extension-risk/"
  },
  "original_language": "en",
  "account": "Security experts discovered over 150 fraudulent Open VSX extensions that impersonated legitimate Visual Studio Code Marketplace tools. Between July 26 and August 1, 77 of these counterfeit extensions targeted developer credentials, source code, and CI/CD systems. They were distributed via unauthorized accounts and exposed data to the newly registered domain mangorbit[.]com. Nineteen of the extensions collected sensitive information including developer machine details, Git repository and CI/CD environment data. By August 3, all 77 extensions had been removed, but installations on developer machines or embedded in development images could persist. The reused identities and listing descriptions of legitimate extensions increased the risk of supply-chain attacks. Manifold Security's investigation revealed that all 77 extensions mimicked the original publishers' details while communicating with the malicious infrastructure. No source-code, credentials, tokens, SSH-keys, or browser-data were stolen in the analyzed packages, but some extensions mistakenly claimed CI values remained on the machine. Developers should regularly inventory installed extensions, review configuration files, and check for suspicious activity involving mangorbit[.]com to mitigate the supply-chain risk.",
  "summary": "Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk. The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic .",
  "key_points": [
    "77 counterfeit Open VSX extensions collected developer data.",
    "Extensions targeted credentials, source code, and CI/CD systems.",
    "All 77 extensions removed by August 3, but persistence risk remains."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}