← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 24, 2026 · 11:11via CyberPress

Open VSX Unblocks 3 Extension IDs Used in Malware Campaign, Complicating Threat Tracking

Brief

Open VSX removed three extension IDs from its malicious-extension list between August 16 and August 20, restoring publishing access to legitimate developers whose identifiers had been hijacked in a large-scale impersonation campaign.

The reversals affect AlDuncanson. react-hooks-snippets , magne-sjaastad. opm-flow-editor-support , and rumbledb. jsoniq-vscode all three previously used by impostors in a 77-extension evil-twin campaign documented by Manifold Security earlier this month, reflecting ongoing challenges in mitigating supply chain attacks across open-source ecosystems.

Open VSX Unblocks 3 Malicious Extension IDs

Each case followed a similar pattern: attackers registered extension names already established in Microsoft’s VS Code Marketplace but not yet claimed on Open VSX, then published malicious lookalikes.

Read more on CyberPress