www.infosecurity-magazine.com 8/5/2026, 3:51:24 PM · external

Harmful VSX plugins siphon data from private repositories and CI

Harmful VSX plugins siphon data from private repositories and CI
CyberSIXT Evidence Panel
Primary Source manifold.security

A recent report by Manifold Security has revealed that counterfeit extensions masquerading as legitimate developer tools on the Open VSX registry have been harvesting sensitive data from private repositories and CI systems. During a week, 77 fake packages were identified, with malicious intent to collect information such as hostname, OS username, git repository details, and CI values.

These extensions had no legitimate functions and were designed to operate undetected, continuing to function even if endpoints were taken down. Open VSX took action to remove these packages, but experts recommend organizations to implement strict protocols in managing extension installations and publisher verifications to safeguard against such threats.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT