<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Malicious-Extensions on CuraSec</title><link>https://curasec.metacog.co.kr/tags/malicious-extensions/</link><description>Recent content in Malicious-Extensions on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/malicious-extensions/index.xml" rel="self" type="application/rss+xml"/><item><title>77 Open VSX extensions caught harvesting developer environment data</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-77-open-vsx-extensions-found-harvesting-developer-info/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-77-open-vsx-extensions-found-harvesting-developer-info/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If your team uses Open VSX (common in VS Code OSS or VSCodium environments), audit installed extensions against the removed list and purge any matches; review extension installation policies in CI/CD or dev container configs to restrict to known-good sources.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for unexpected outbound connections from IDE processes (code, codium) to unknown endpoints; consider hunting for extension-related network activity in EDR telemetry from developer workstations over the past 90 days.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This incident illustrates ongoing supply-chain risk in developer tooling marketplaces; useful context for evaluating software vetting policies in engineering onboarding, but no immediate leadership action required.&lt;/li>
&lt;/ul></description></item><item><title>Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Dev Data</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrat/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrat/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If your team uses Open VSX-sourced extensions (common in Theia, Gitpod, or VS Code OSS environments), audit installed extensions against the 77 removed packages and remove any installed between July 26–August 1, 2026; check build/dev environments for unexpected outbound connections during that window.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for anomalous outbound traffic from developer workstations and CI runners between July 26 and August 1, 2026 that may indicate data exfiltration from compromised extensions; correlate against Open VSX extension install events in endpoint logs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> This incident illustrates supply-chain risk in developer tooling marketplaces; work with engineering leads this quarter to establish an approved-extension policy and inventory for IDE plugins used across the org.&lt;/li>
&lt;/ul></description></item></channel></rss>