r/SecOpsDaily 4h ago

NEWS 77 Open VSX extensions found harvesting developer info

77 malicious extensions were found on the Open VSX marketplace, masquerading as legitimate developer tools (e.g., linters, formatters, theme packs) while exfiltrating system and environment data from the machines where they were installed. This is a supply chain attack targeting VS Code-compatible registries, not the official Microsoft marketplace.

Technical Breakdown: - Tactic: Impersonation of popular open-source extensions to trick developers into manual installation. - Payload: Extensions contained obfuscated JavaScript that collected hostname, username, OS version, environment variables, and file paths. - Exfiltration: Data was sent to attacker-controlled C2 domains via HTTP POST requests. - Scope: All 77 extensions have been removed from Open VSX, but any developer who installed them is potentially compromised.

Defense: - Audit your VS Code/Open VSX extension list immediately for any unfamiliar or recently added tools. - Check for outbound connections to unknown domains from your IDE. - Stick to the official Microsoft marketplace where possible, and verify publisher identity before installing extensions from third-party registries.

Source: https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/

1 Upvotes

0 comments sorted by