← Blog · · df00tech

77 Open VSX Extensions Caught Impersonating Dev Tools, Harvesting Developer Data

security-news campaign

What Happened

BleepingComputer reports that 77 extensions on the Open VSX marketplace were found impersonating legitimate developer tools while covertly transmitting information about the systems and development environments in which they were installed. Open VSX is the open-source extension registry used by VS Code-compatible editors such as VSCodium, Eclipse Theia, and others that don't use Microsoft's official Visual Studio Marketplace.

Why It Matters for Defenders

Extension marketplaces are a high-trust, low-scrutiny supply chain vector: developers routinely install editor extensions with broad filesystem and process access, often without the same vetting applied to application dependencies. Extensions posing as well-known tools can blend into a developer's normal workflow, making the exfiltration of environment and system details ordinary-looking. Organizations that permit or don't restrict Open VSX-based editors on developer workstations are directly exposed, and any credentials, source code, or internal tooling details visible from a compromised dev environment could be at downstream risk.

What Defenders Should Watch For

  • Inventory installed extensions across VS Code-compatible editors (VSCodium, Theia, Gitpod, etc.) on developer endpoints, not just official VS Code Marketplace installs.
  • Compare installed extension names/publishers against known-legitimate tools; be alert to typosquatted or impersonating publisher names.
  • Monitor outbound network connections initiated by editor/extension-host processes for unexpected destinations, especially shortly after extension install or editor startup.
  • Review endpoint or EDR telemetry for extension-host processes reading system/environment metadata (hostname, OS info, installed tooling) and sending it externally.
  • Consider restricting extension installation sources to vetted/allow-listed publishers via policy where supported, and educate developers to verify publisher identity before installing.

This is a developing story based on a single third-party report, and the full list of affected extensions and the extent of data harvested were not detailed here. Defenders should treat this as an early signal to review Open VSX exposure rather than a confirmed, fully scoped incident. For the original reporting, see BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.