Fake Open VSX Extensions Hijack High-Trust Namespaces
Fake Open VSX extensions have been hijacking high-trust namespaces on the Open VSX Registry, including AMD, Azure, Salesforce, Hyperledger, and a U.S. government agency.
The malicious extensions silently harvest Git and CI metadata from developer and CI environments while posing as legitimate tools.
The 77 counterfeit extensions were removed by Open VSX Extensions on August 3, 2026, but the deployed code will continue to load the extension locally and transmit data.