A surge of counterfeit Open VSX extensions has revealed how easily a familiar tool can turn into an unauthorized data collection channel This article explores malicious extensions lego. . Private repository names, project paths, branch details, and CI identifiers reveal an organization's internal development activities, making them useful for targeted phishing, follow-on intrusion attempts, or mapping software supply chains.

More serious variants also inspected Git metadata, pulling the host and organization from origin and upstream remote URLs, domain portions of configured commit emails, current branch information, and latest commit identifiers. The script evaluated GitHub Actions, GitLab CI, Azure DevOps, Buildkite, CircleCI, Codespaces, and Gitpod for value checks.

Reviewing runtime behavior, controlling automated installs, and validating publisher identity can significantly reduce the risk that a copied name becomes a gateway into private engineering data across distributed software development teams globally. **Malicious extensions:** - **lego-education.ev3-micropython version 0.0.2**: Observed counterfeit Open VSX extension - **better-ts-errors.better-ts-errors version 0.0.1**: Observed counterfeit Open VSX extension - **groksrc.ruby version 0.0.1**: Observed counterfeit Open VSX extension - **maptz.regionfolder version 0.0.1**: Observed counterfeit Open VSX extension - **mitsuhiko.insta version 0.0.1**: Observed counterfeit Open VSX extension - **SBSnippets.pytorch-snippets version 0.0.1**: Observed counterfeit Open VSX extension - **slb235.vscode-coffeelint version 0.0.1**: Observed counterfeit Open VSX extension - **amd.gaia-vscode version 0.0.1**: Observed reconnaissance extension - **artsy.artsy-studio-extension-pack version 0.0.1**: Observed reconnaissance extension - **configcat.configcat-feature-flags version 0.0.1**: Observed reconnaissance extension