Evil Twin Campaign Targets Open VSX Marketplace to Profile Developers
Manifold Security uncovered 77 malicious extensions impersonating major tech brands to harvest environment metadata.
Manifold Security has identified a sophisticated "evil twin" campaign on the Open VSX marketplace that targeted developers by impersonating legitimate software tools. The operation, which ran from July 26 to August 1, 2026, focused on harvesting system and development environment metadata rather than immediate credential theft.
According to Manifold Security, 77 malicious extensions were deployed to the marketplace, all of which communicated with the domain mangorbit[.]com. This domain was registered on July 15, 2026, just days before the campaign began. The extensions impersonated namespaces associated with high-profile organizations, including AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and a U.S. government agency. By mirroring the names and descriptions of trusted tools, the attackers deceived users into installing counterfeit packages.
The Scope of Reconnaissance
The campaign utilized two distinct levels of data collection. Fifty-eight of the extensions collected minimal data, such as the user's hostname, workspace folder, and editor version. However, a more aggressive subset of 19 extensions performed deep reconnaissance, exfiltrating extensive metadata including OS usernames, platform architecture, and CI identifiers.
Specifically, these reconnaissance extensions targeted the developer's workflow infrastructure. They exfiltrated Git remote hosts, organization names, and developer email domains. The attackers also harvested identifiers from a wide array of platforms, including GitHub, GitLab, Azure DevOps, Buildkite, CircleCI, GitHub Codespaces, and Gitpod.
Implications for the Supply Chain
This campaign highlights a shift toward high-fidelity reconnaissance in supply chain attacks. While the extensions did not steal source code or authentication tokens, the data they collected allows attackers to map an organization's internal infrastructure. By profiling private repository names and CI/CD pipelines, threat actors can identify specific vulnerabilities and targets for more devastating, tailored attacks in the future.
Open VSX serves as an open-source alternative to the Microsoft Visual Studio Marketplace. This breach underscores the risks inherent in third-party extension ecosystems where impersonation can bypass user scrutiny and compromise the integrity of the development environment.
Current Status
The threat was neutralized shortly after discovery. Manifold Security and marketplace administrators ensured that all 77 malicious extensions were removed from the Open VSX marketplace by August 3, 2026. Security teams are now advised to monitor for any unusual activity originating from the mangorbit[.]com domain within their development environments to ensure no persistent remnants of the reconnaissance tools remain active.