
Extension Confusion Lets Attackers Hijack Trusted Names Across VS Code Registries
A coordinated campaign used 77 counterfeit VS Code extensions to collect developer and CI environment data through Open VSX. The packages copied trusted extension names, namespaces, and descriptions, but were published from unrelated pseudonymous accounts. Between July 26 and August 1, 2026, all 77 extensions contacted the same newly registered domain, mangorbit[.]com. Most used version […]
The post Extension Confusion Lets Attackers Hijack Trusted Names Across VS Code Registries appeared first on Cyber Security News.