Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Open VSX Unblocks Extension IDs Used in Malware Campaign

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
1,220
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Open VSX removed three extension IDs from its malicious-extension list after legitimate publishers demonstrated ownership and sought to publish official versions of extensions that had been impersonated in a 77-package “evil-twin” malware campaign. The cases involving React Hooks Snippets, OPM Flow Editor Support, and RumbleDB JSONiq show how attackers can claim names already established in Microsoft’s VS Code Marketplace but unclaimed on Open VSX, creating later conflicts when real maintainers arrive. Although unblocking IDs enables legitimate distribution, it also makes ID-only malware tracking unreliable because current blocklists may no longer reflect malicious versions previously published under the same name. Open VSX’s Git history retains evidence of the changes, but organizations that track only extension IDs may be unable to distinguish malware from later legitimate releases. The report notes earlier examples of reclaimed or corrected IDs and the absence of a published general policy for handling them. It recommends that users and security teams track precise versions, file hashes, publisher identities, and source repositories, while maintainers should claim their Open VSX namespaces proactively and artifact-level security scanning should supplement name-based blocklists.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.