INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Data

| 2026-08-05 09:23 LOW HIGH DATA BREACH
Executive Summary
AI-generated
A cluster of 77 malicious extensions on the Open VSX marketplace, uploaded between July 26 and August 1, 2026, has been found to impersonate legitimate developer tools while transmitting information about systems and development environments. The attackers are believed to be behind these malicious extensions, which were removed from Open VSX as of August 3, 2026. These affected approximately 77 developers who installed the malicious extensions on their systems. The attack works by displaying a status bar item with a message stating they are active before firing data exfiltration steps, sending information to "[IOC HIDDEN • LOGIN REQUIRED]". As of now, these malicious extensions have been removed from Open VSX and no further updates or incidents have been reported regarding this incident.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ua•••••.dsdl
ar•••••.artsy
os•••••.sfmc
ob•••••.oscript
ex•••••.json
ex•••••.js
de•••••.json
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Mini Shai-HuludMini Shai-HuludShai-HuludShai-Hulud
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎July 15, 2026
Threat actors used a Mini Shai-Hulud variant delivered through an obfuscated Bun-based JavaScript payload to target Visual Studio Code repositories, exfiltrating developer data.
infrastructure Visual Studio Code
‎August 3, 2026
Threat actors reused real Microsoft VS Code Marketplace extension names and descriptions to publish malicious Evil Twin extensions with low version numbers, exfiltrating developer data through a shared domain.
infrastructure Vs Code
infrastructure 0.0.1
‎2026/08/05
A cluster of 77 malicious extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about installed systems and development environments.
infrastructure 60 installed extension IDs
data_breach 77 Extensions Exfiltrating Developer Data
Tactical Metrics
Metrics
infrastructure
60
Installed Extension Ids
Metrics
infrastructure
‎Vs Code
Affected Product
Metrics
infrastructure
‎0.0.1
Software Version
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Metrics
data_breach
77
Extensions Exfiltrating Developer Data
Intelligence Sources