Affected Systems

Open VSX marketplace users who installed any of 77 counterfeit "evil twin" extensions between July 26 and August 1, 2026. Extensions impersonated legitimate tools from AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and a U.S. government agency. All 77 packages communicated with mangorbit[.]com infrastructure.

Exploitation Status

Active campaign detected in the wild from July 26 to August 1, 2026. All 77 malicious extensions were removed from Open VSX by August 3, 2026, but remain installed on affected developer systems. No follow-on exploitation observed yet; campaign purpose remains unclear.

Business Impact

Developer workstations and CI/CD environments exposed organizational metadata including Git repository structure, private repo names/paths, developer email domains, installed extensions, and CI platform identifiers (GitHub, GitLab, Azure DevOps, Buildkite, CircleCI, Codespaces, Gitpod). While source code, credentials, tokens, and SSH keys were not accessed, the reconnaissance data enables targeted supply chain attacks and social engineering. Extensions persist on systems despite marketplace removal.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Audit all developer workstations and CI/CD systems for the 77 extension IDs listed in the Manifold Security report and manually uninstall any matches
  • Block mangorbit[.]com and all subdomains (pulse.mangorbit[.]com, pulse2.mangorbit[.]com, api.mangorbit[.]com, cb.mangorbit[.]com) at DNS and firewall level
  • Search proxy and DNS logs for connections to mangorbit[.]com since July 26, 2026 to identify compromised systems and assess exposure scope
  • Review workspace configuration files (.vscode, .theia, etc.) for references to suspicious extension IDs with version 0.0.1
  • Implement extension vetting policy requiring approval before installation and restrict Open VSX extension sources to verified publishers only