In brief: 77 extensions disguised as legitimate tools on the Open VSX marketplace harvested data from users’ development environments.
Security researchers have identified 77 extensions on the Open VSX marketplace that posed as legitimate developer tools while collecting information about the installed systems and development environments. Affected are users of VS Code-compatible editors such as VSCodium, which use Open VSX instead of the official Microsoft marketplace as their extension source.
The 77 affected extensions on the Open VSX marketplace posed as well-known and frequently used developer tools in order to gain trust. In the background, however, they transmitted telemetry data about the respective system and development environment to external servers. Open VSX is an open-source alternative to the official Visual Studio Code Marketplace and is used, among others, by editors such as VSCodium, Gitpod, or Eclipse Theia as the default source for extensions, since these are not permitted to access Microsoft’s own marketplace for licensing reasons.
For engineering teams, this creates a concrete risk in the software supply chain: extensions run with the editor’s permissions and typically have access to source code, environment variables, installed packages, and other metadata of the development machine. Since Open VSX follows an open publishing model, the barrier to submitting malicious or deceptively named packages is lower than with more heavily curated marketplaces. Organizations using VSCodium, Gitpod, Eclipse Theia, or other Open VSX-based editors should assume that similar incidents can recur.
In practice, it is advisable to inventory installed extensions in development environments and check them against known malicious package names, to verify publisher identities and download counts before installation, and to introduce internal allowlists for approved extensions. Network-side monitoring for unusual outbound connections from developer machines can additionally help detect data exfiltration by compromised or malicious extensions at an early stage.
Source: www.bleepingcomputer.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.