CyberSecurity News
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
AI summary
A group of 77 malicious extensions were discovered on the Open VSX marketplace, disguising themselves as legitimate developer tools. These extensions were designed to collect and transmit information about the systems and development environments where they were installed. The malicious extensions were uploaded to the repository over a period of several days. They have since been removed from Open VSX. The extensions were identified as "evil twin" packages, implying they mimicked legitimate tools. The removal of the extensions was taken after their malicious nature was uncovered.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

