- Sources: coverage
- Summary: Manifold Security found extensions on Open VSX impersonating real VS Code Marketplace packages, published between 2026-07-26 and 2026-08-01 and all reporting to mangorbit[.]com. 19 of them collected Git remote hosts, configured email domains, branch and HEAD commit, and identifiers from GitHub, GitLab, Azure DevOps, Buildkite, CircleCI, Codespaces and Gitpod. The other 58 mainly sent hostname, with some variants adding workspace folder name and editor version. Open VSX removed them by 2026-08-03. The coverage names no individual extension, and states that Manifold's own report carries the extension IDs to check systems and workspace configuration files against, and that all 77 packages contact mangorbit[.]com.
- Why it matters: Registry removal does not uninstall an extension, so a reader needs the extension IDs from Manifold's report to find affected machines, and blocking mangorbit[.]com at the network edge cuts the single exfiltration domain shared by all 77 packages in the meantime.
send feedback on this story