← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 24, 2026 · 05:48via Socket Security Blog

Open VSX Unblocks Extension IDs Used in Malware Campaign

Brief

Over a five-day period from August 16 through August 20, the registry unblocked AlDuncanson. react-hooks-snippets , magne-sjaastad. opm-flow-editor-support , and rumbledb. jsoniq-vscode . All three IDs had been used by impostors in the 77-extension evil-twin campaign documented by Manifold Security earlier this month. Legitimate versions of the OPM and RumbleDB extensions are now live.

React Hooks Snippets has been unblocked, but its legitimate Open VSX listing had not appeared as of publication.

The cleanup addresses a problem created by namesquatting across two separate marketplaces. It also exposes the limits of tracking a malicious extension by ID alone. An identifier can first belong to an impostor and later return under the control of the project it copied, while the malicious artifact remains part of the incident history.

Read more on Socket Security Blog