Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Summary
A cluster of 77 malicious 'evil twin' extensions were discovered on the Open VSX marketplace, impersonating legitimate developer tools. These extensions were designed to exfiltrate sensitive information about the developer's systems and development environments. All identified malicious packages have since been removed from the marketplace.
IFF Assessment
The discovery of malicious extensions designed to exfiltrate developer data represents a significant threat to developers and their intellectual property.
Defender Context
This incident highlights the ongoing risk of supply chain attacks within the developer ecosystem, where seemingly legitimate tools can be compromised to exfiltrate sensitive data. Defenders should be vigilant about the extensions they install, scrutinize their permissions, and stay informed about potential threats targeting developer environments.