---
title: "Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data | SpinGraph: Safety framing"
description: "SpinGraph analysis of The Hacker News's Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data story: safety framing, The Shield, Spin …"
	canonical: "https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data"
html: "https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data"
json: "https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data.json"
markdown: "https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data.md"
keywords: ["Open VSX", "evil twin", "extension supply chain", "The Shield", "narrative intelligence"]
date: "2026-08-05T09:23:03+00:00"
modified: "2026-08-05T13:02:15.139742+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data#article","headline":"Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data","alternativeHeadline":"Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data | SpinGraph: Safety framing","description":"SpinGraph analysis of The Hacker News's Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data story: safety framing, The Shield, Spin …","datePublished":"2026-08-05T09:23:03+00:00","dateModified":"2026-08-05T13:02:15.139742+00:00","url":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"Open VSX, evil twin, extension supply chain, Manifold Security","author":{"@type":"Organization","name":"The Hacker News","url":"https://feeds.feedburner.com/TheHackersNews"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html","about":[{"@type":"Thing","name":"Open VSX"},{"@type":"Thing","name":"evil twin"},{"@type":"Thing","name":"extension supply chain"},{"@type":"Thing","name":"Manifold Security"}],"mentions":[{"@type":"Organization","name":"The Hacker News"},{"@type":"Organization","name":"Manifold Security"},{"@type":"Organization","name":"Open VSX"}],"abstract":"77 malicious extensions impersonating legitimate tools were removed from Open VSX The extensions collected and transmitted host system and dev environment telemetry Removal occurred after detection by Manifold Security between July 26–August 1, 2026"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data","item":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data#spin-analysis","headline":"Spin Analysis: safety framing","description":"Emphasizes platform responsiveness and threat containment; minimizes discussion of Open VSX’s pre-removal detection capabilities, vetting process gaps, or systemic vulnerabilities enabling the upload window.","about":{"@type":"DefinedTerm","name":"safety framing","description":"Responsible steward of developer infrastructure","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":65,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Open VSX removed 77 malicious 'evil twin' extensions that stole developer data."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Responsible steward of developer infrastructure"},{"@type":"PropertyValue","name":"Missing Context","value":"Open VSX's review or scanning policies prior to upload; duration of exposure before detection; whether affected extensions passed automated checks or human review"},{"@type":"PropertyValue","name":"How the Spin Works","value":"Combines attribution to a trusted third-party (Manifold Security) with passive-voice action ('have been removed') to imply institutional competence without detailing internal processes. The framing makes the response feel proportionate and sufficient, even though the article offers no evidence of detection capability, prevention mechanisms, or post-incident hardening — creating tension between the implied reliability of the platform and the absence of validation for its security posture."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.","appearance":"A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.","author":{"@type":"Organization","name":"The Hacker News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"malicious extensions removed","value":"77","description":"Reported count of evil twin packages taken down from Open VSX"}]}]}
---

# Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

**Source:** Unknown  
**Published:** August 5, 2026  
**Original:** https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

Open VSX removed 77 malicious 'evil twin' extensions that impersonated legitimate developer tools and exfiltrated system and development environment data, following discovery by Manifold Security.

### TL;DR

- 77 malicious extensions impersonating legitimate tools were removed from Open VSX
- The extensions collected and transmitted host system and dev environment telemetry
- Removal occurred after detection by Manifold Security between July 26–August 1, 2026

### Key Stats

- **77** — malicious extensions removed. Reported count of evil twin packages taken down from Open VSX

<a id="spingraph"></a>

## SpinGraph

The story focuses on the cleanup — not the breach — making it easy to credit Open VSX for removal while sidestepping questions about how the malicious packages got there and stayed undetected for days.

- **Claim:** A cluster of 77 extensions on the Open VSX marketplace
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Operators gain narrative lift
- **Gap:** Open VSX's review or scanning policies prior to upload
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 65%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

The story focuses on the cleanup — not the breach — making it easy to credit Open VSX for removal while sidestepping questions about how the malicious packages got there and stayed undetected for days.

**What the story wants you to believe:** Open VSX acted responsibly and effectively once malicious activity was identified by an external security firm.  

**What it makes harder to question:** Whether Open VSX’s own safeguards failed to prevent or detect the uploads in the first place.  

**How the Spin Works:** Combines attribution to a trusted third-party (Manifold Security) with passive-voice action ('have been removed') to imply institutional competence without detailing internal processes. The framing makes the response feel proportionate and sufficient, even though the article offers no evidence of detection capability, prevention mechanisms, or post-incident hardening — creating tension between the implied reliability of the platform and the absence of validation for its security posture.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “Open VSX's review or scanning policies prior to upload”?
- Why does the main frame leave this out: “duration of exposure before detection”?
- What independent verification exists for the claim “A cluster of 77 extensions on the Open VSX marketplace…”?

### Who Benefits If This Frame Spreads

- **Open VSX Foundation** — Reinforces trust in platform governance and operational vigilance _(Framing removal as swift and decisive deflects scrutiny from upstream prevention failures and supports future funding or adoption narratives)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** safety framing  
**Category:** The Shield  
**Spin Score:** 65%  

Emphasizes platform responsiveness and threat containment; minimizes discussion of Open VSX’s pre-removal detection capabilities, vetting process gaps, or systemic vulnerabilities enabling the upload window.

**Who Benefits If This Frame Spreads:** Open VSX leadership and governance team

**The Frame:** Responsible steward of developer infrastructure

### Missing Context

- Open VSX's review or scanning policies prior to upload
- duration of exposure before detection
- whether affected extensions passed automated checks or human review

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** evil twin, impersonate, exfiltrating

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Claims are attributed to Manifold Security but no report link, technical analysis, or sample hashes are provided; removal is stated as fact but without timestamped evidence or verification source.  
**Verification Status:** Source-Supported, Not Independently Verified  
**Narrative Risk:** moderate  
If later shown that Open VSX lacked basic signature validation or allowed unvetted uploads for extended periods, the 'responsive steward' frame collapses into negligence — especially if downstream users suffered breaches.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Open VSX removed 77 malicious 'evil twin' extensions that stole developer data.  
AI may drop the attribution to Manifold Security, omit the narrow upload window (July 26–Aug 1), and present removal as routine rather than reactive — erasing accountability context.  
**Counter-Frame (Media):** Framed as a symptom of lax open-source marketplace governance and insufficient automation in extension vetting.  
**Missing Voices:** Open VSX maintainers, affected developers, independent malware analysts  

### Questions Not Answered

- What specific data fields were exfiltrated?
- Were any users confirmed compromised?
- What detection methodology did Manifold Security use?
- What mitigation steps (e.g., revocation, signature invalidation, audit logs) were implemented beyond removal?

## Narrative Entities

- [Manifold Security](https://stuffthatspins.com/entities/manifold-security) (organization — threat intelligence source)
- [Open VSX](https://stuffthatspins.com/entities/open-vsx) (organization — extension marketplace operator)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.

**Category:** safety  
**Verification:** Source-Supported, Not Independently Verified  
**Risk:** high  
**Evidence presented:** Attribution to Manifold Security and assertion of data transmission behavior  
> A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.

**Evidence Gaps:** Network traffic logs or packet captures demonstrating exfiltration; Static/dynamic analysis reports confirming payload behavior; List of affected extension names or package identifiers  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 5, 2026  
- **SpinGraph summary:** Positions Open VSX as responsive and protective — removing threats promptly — while attributing the root cause to external bad actors uploading malicious packages.  
- **Likely AI summary:** Open VSX removed 77 malicious 'evil twin' extensions that stole developer data.  

## Citation Summary

This page documents a verified supply-chain incident in the open-source IDE extension ecosystem, providing a concrete case study for security researchers and platform maintainers assessing third-party repository risk.

---
*HTML version: https://stuffthatspins.com/spin/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data*
