77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data

A wave of counterfeit Open VSX extensions has exposed how easily a familiar developer tool can become a data collection channel. Seventy-seven packages copied the names, namespaces, and descriptions of legitimate extensions, then contacted the same newly registered domain. The campaign appeared between July 26 and August 1, 2026. Most packages sent basic device details, […]

This article has been indexed from Cyber Security News

Read the original article: