A coordinated operation utilized 77 counterfeit VS Code extensions to gather developer and CI environment data through Open VSX. The packages mimicked trusted extension names, namespaces, and descriptions while being published under pseudonymous accounts from unrelated domains. The campaign utilized two distinct payload types: lightweight extensions that were approximately 1.6KB to 3.3KB in size and sent along with the hostname, sometimes including the workspace folder name or VS Code version.

Their payloads, ranging from around 10KB, began activating shortly after editor startup and collected extensive information such as the hostname, OS username, VS Code version, machine ID, platform, architecture, locale, timezone, and workspace filesystem path.

They also examined Git metadata to gather remote host and organization details, the domain portion of configured commit emails, active branches, and the latest commit SHA. Most notably, reconnaissance payloads retrieved CI environment values, including GitHub repository names, GitLab project paths, Azure DevOps collection URIs, Buildkite organization slugs, CircleCI project names, Codespaces names, and Gitpod workspace URLs. Automated tools, DevContainer configurations, provisioning scripts, and AI agents can install extensions by name without evaluating publisher history, download counts, verification status, or source-repository lineage.

Utilize in-browser data inspection from ANY.RUN for faster detection, investigation, and response, enhancing your SOC’s effectiveness while reducing Mean Time To Repair (MTTR).