28 Evil-Twin Open VSX Extensions Coordinated Beacons
Score: 8/10

28 Evil-Twin Open VSX Extensions Coordinated Beacons

An unidentified operator deployed 28 malicious 'evil-twin' Open VSX extensions that exfiltrate developer environment data to i.apee.my.id using multiple network evasion techniques.

Executive Summary

On August 12, 2026, a coordinated campaign targeted the Open VSX registry by uploading at least 28 counterfeit extensions within a single hour. These extensions impersonated legitimate projects and publishers to trick developers and automated build systems into installing malicious payloads. The primary objective is developer environment reconnaissance, harvesting hostnames, editor types, and git email addresses.

The technical tradecraft exhibited a high degree of iteration, with the operator testing four distinct exfiltration variants: standard HTTP POSTs, DNS tunneling via subdomains, hidden VS Code terminals executing curl, and bundled native ELF/Node-API binaries. To maintain persistence on the registry, the threat actor followed malicious uploads with 'clean' decoy versions (v0.0.3) to dilute trust and evade snapshot-based security reviews.

This campaign highlights a critical vulnerability in modern developer workflows where automated tools and hurried searches may resolve extension names to malicious 'evil-twin' packages on secondary registries. Organizations should treat unverified publishers and recently registered namespaces as high-risk blocking conditions.

Key Details

Threat Name

i.apee.my.id Evil-Twin Campaign

Affects

—

Adversary

—

Malware/Tools

WhiteCobra, jsononifier, GLASSWORM, PackRAT, RustImplant, SleepyDuck

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources