# Seventy-Seven Fake Extensions Were Quietly Mapping Developer Machines — and CI Pipelines
Open VSX is supposed to be the clean alternative. Developers use it precisely because they want to escape Microsoft's telemetry grip — it's the marketplace of choice for VSCodium, Gitpod, and anyone who made a deliberate decision to build on a more open stack. That makes what Manifold Security found last week particularly sharp: 77 malicious extensions, uploaded over six days, using the cover of legitimate tools to do exactly the surveillance those developers were trying to avoid.
The campaign ran from July 26 to August 1. The packages were pulled August 3. The window was short. The data collection was not.
## Not Smash-and-Grab — Reconnaissance Infrastructure
Security researchers Ax Sharma and Cody Nash split the campaign into two tiers, but the more important distinction isn't about the data volume — it's about what the attackers were actually building.
The 58 lighter extensions grabbed hostnames, maybe a workspace folder name or editor version. That's noise, mostly. But the 19 heavier ones were doing something else entirely. They enumerated up to 60 installed extension IDs per machine. They pulled the developer's configured email domain from Git config. They harvested the current branch and HEAD commit SHA. They read active CI environment variables — not just GitHub Actions, but Azure DevOps collection URIs, Buildkite organisation slugs, CircleCI project usernames, Codespace names, and Gitpod workspace context URLs.
That last list deserves to sit with you for a moment. A threat actor who knows what CI platform a developer is using, what org they're inside, and what their workspace path looks like has a remarkably complete picture of where sensitive code lives and how it flows to production. This isn't credential theft. It's target identification.
The exfiltration domain — mangorbit[.]com — was registered July 15, eleven days before the first package went up. The attackers planned this. They also built in a DNS TXT fallback: if the primary domain gets blocked or seized, the malicious code queries DNS for a backup exfiltration endpoint. And the recon variant runs on a delayed retry schedule — roughly 15 minutes, 50 minutes, three and a half hours, then recurring — which means a machine that wasn't active at first launch still gets hit.
This is not someone testing ideas. This is operational infrastructure.
## The Evil Twin Playbook
The technique itself — copying the name, namespace, and description of a legitimate extension, publishing under an unrelated account at a suspiciously low version number like 0.0.1 — is a known supply chain pattern. We've seen it in npm, PyPI, and against the VS Code Marketplace proper. The twist here is that Open VSX operates with less formal vetting than Microsoft's marketplace, and its user base skews toward developers who are already privacy-conscious, technically sophisticated, and often working inside environments with elevated access.
The 19 impersonated extensions included real tools from recognized publishers: iotaledger.iota-move, configcat.configcat-feature-flags, ssagov.uef-snippets, move.move-analyzer. None of the fakes delivered any of the advertised functionality. Instead, they displayed a status bar item claiming to be active — plausible enough that a developer who installed one might dismiss the absence of features as a configuration issue and move on.
Framing the collection as "anonymous usage metrics" is a nice touch. Every legitimate developer tool sends something somewhere. Most developers have learned to click through those notices. The attackers are exploiting exactly that habituation.
## What the Telemetry Opt-Out Check Reveals
There's one detail in Manifold's report that's easy to miss: the recon extensions read the editor's own telemetry opt-out setting and then report whether it's enabled.
Think about what that tells the operator on the other end. They now know which infected machines belong to developers who are specifically privacy-aware — people who dug into settings and turned off data collection. That's a self-selecting list of security-conscious targets. It's also a filter for environments where anomalous outbound traffic is more likely to be noticed. This isn't data for data's sake; it's profiling for operational risk management.
## What Defenders Actually Need to Do
The immediate response is straightforward: anyone using Open VSX should audit installed extensions, cross-reference against the 19 names listed in Manifold's disclosure, and check network logs for connections to mangorbit[.]com. If the domain appears in logs, treat it as a confirmed compromise and begin incident response.
The harder problem is structural. Extension marketplaces — all of them — need publisher identity verification that doesn't rely on namespace conventions or visual similarity detection. Manifold found this campaign through code analysis. That's a human-hours-intensive process that doesn't scale to continuous monitoring. Open VSX operates with limited resources compared to Microsoft's marketplace; the community building on it needs to fund the security infrastructure that makes it trustworthy.
For teams running CI pipelines: if any developer on the team used VSCodium or another Open VSX-dependent editor in late July or early August, you should audit your CI environment variable exposure. The 19 recon extensions were specifically collecting org-level CI identifiers. If an attacker now knows your Buildkite slug and your Azure DevOps collection URI, they know where to probe next.
---
## HackWire Analysis
The timing of this campaign maps onto a pattern we've been watching since early 2025: systematic reconnaissance targeting developer environments specifically because developers are the path of least resistance into production infrastructure.
Prior to this, we saw similar campaigns against the VS Code Marketplace proper — extensions masquerading as popular tools, collecting environment data with varying levels of sophistication. What's shifted is the targeting. Earlier campaigns grabbed credentials directly when they could. This one didn't. It built a map. That suggests either that the operators are in an earlier phase of a longer campaign, or that they're selling the reconnaissance data rather than exploiting it directly.
The Open VSX angle is also worth flagging for an underreported reason: VSCodium and related forks are disproportionately used in security research environments, by developers building open-source security tooling, and inside organizations that have mandated open-source toolchains for compliance reasons. The irony of malware hitting privacy-focused users is one story. The operational reality that some percentage of those 77-extension victims may have been security researchers or engineers at infrastructure companies is a different, more consequential one.
The CI environment variable harvest is what I'd focus on for the next 30 days. That data is now presumably in an operator's hands. Watch for targeted spear-phishing, credential-stuffing attempts against GitHub orgs matching the collected slugs, or unusual activity in Azure DevOps tenants. The reconnaissance phase is over. Whatever comes next was always the point.
— HackWire Editorial
---
## Related Coverage