AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

11:23 · August 5, 2026 · Hacker News AI Section

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of

Summary

A cluster of 77 malicious extensions was removed from the Open VSX registry after researchers at Manifold Security identified them impersonating legitimate developer tools. Uploaded between 26 July and 1 August 2026, the packages were taken down on 3 August. Fifty-eight of them performed lightweight exfiltration of the host machine’s hostname and, in some cases, the workspace folder name or editor version. The remaining nineteen collected a broader set of identifiers, including operating-system username, editor version and machine ID, platform architecture, locale, timezone, and the full path of the open workspace.

All 77 extensions reused the names, namespaces and descriptions of existing Open VSX packages but were published from unrelated accounts at low version numbers such as 0.0.1. They replaced the bundled extension.js with code that transmitted collected data to the domain mangorbit.com, registered eleven days before the first malicious uploads. The extensions displayed a status-bar notification claiming to be active, then performed the exfiltration under the guise of anonymous usage metrics. The reconnaissance variants included retry logic that re-attempted collection at intervals up to seven days and queried DNS TXT records for fallback exfiltration endpoints if the primary domain became unavailable. They also checked whether the workspace’s devcontainer.json or .vscode/extensions.json referenced the extension, allowing the operators to distinguish configuration-driven installs from manual ones.

The same disclosure described a separate supply-chain campaign, named ChainDrop, that compromised 450 unique npm packages and 2,244 artifacts. Attackers used stolen maintainer tokens to publish trojanized versions containing a Mini Shai-Hulud variant: a self-propagating credential-stealing worm delivered through an obfuscated Bun-based payload executed via the npm preinstall hook. The malware further leveraged harvested GitHub credentials to inject malicious configuration files into .claude and .vscode directories, creating persistence across cloned repositories and an additional vector that reaches both human developers and AI coding agents. The activity shares techniques with earlier Shai-Hulud operations but remains unattributed.

Why it matters

This article highlights emerging supply chain threats targeting developer environments and AI coding agents like Claude. Security professionals in the Dutch AI market must address these vectors to secure their CI/CD pipelines and prevent data exfiltration.

More in this beat
ChainDropcoding-agentsgithubnpmopen-source-securityOpen VSXshai-huludthreat-and-vulnerability-updates
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

11:13 · June 9, 2026

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Python is the foundational programming language for AI development. Security professionals in the Dutch AI market must be aware of PyPI supply chain attacks to secure their AI development environments, protect proprietary models, and prevent credential theft.

Relevance 65 · Audience 85

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

20:37 · July 22, 2026

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

This article is highly relevant for security professionals as it highlights how AI is fundamentally altering the economics and operations of vulnerability management and bug bounties. Dutch enterprises running bug bounty programs or utilizing AI for code security must adapt to these shifts to effectively manage AI-generated reports and leverage new AI security models.

Relevance 75 · Audience 90

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

20:23 · July 20, 2026

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Directly addresses AI-specific security risks and privacy threats via malware in AI tooling ecosystems, with actionable recommendations applicable to Dutch teams using GitHub, MCP servers, or agentic AI. Aligns with EU data protection needs due to data-stealing payloads.

Relevance 85 · Audience 90

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

18:47 · August 11, 2026

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

This article demonstrates the practical application of AI agents in discovering complex vulnerability chains in widely used enterprise software. It provides crucial insights into how AI is accelerating offensive security capabilities, which Dutch enterprises must understand to defend against increasingly sophisticated cyberattacks.

Relevance 85 · Audience 95

Your agent needs a computer, not a container — introducing @cloudflare/computer

15:15 · August 3, 2026

Your agent needs a computer, not a container — introducing @cloudflare/computer

This article is relevant for security professionals as it introduces a new paradigm for sandboxing AI agent execution. The built-in gating, auditing, and isolated environments provide essential mechanisms for securing autonomous AI systems and mitigating risks associated with untrusted code execution.

Relevance 65 · Audience 60

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

10:04 · July 28, 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

This article is highly relevant for security professionals as it demonstrates the practical application of AI in offensive cybersecurity and vulnerability research. It highlights a specific Linux kernel vulnerability that Dutch enterprises must patch, while also signaling the evolving threat landscape where AI accelerates exploit development.

Relevance 75 · Audience 90