ZeroHour

Search: “Workspace ONE”

62 stories

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

77 malicious 'evil twin' Open VSX extensions impersonated developer tools and exfiltrated hostnames and detailed workspace reconnaissance to mangorbit.com.

Manifold Security found 77 extensions uploaded to the Open VSX marketplace between July 26 and August 1, 2026 that impersonate real Microsoft VS Code Marketplace tools, with all 77 sending data to mangorbit.com. 58 lightweight variants exfiltrate the hostname, while 19 recon variants collect editor details, OS username, Git remote hosts, CI environment variables (GitHub, GitLab, Azure DevOps, Buildkite, CircleCI, Codespaces, Gitpod), and installed extension IDs. The recon variant retries for up to seven days and can fall back to a DNS TXT record for exfiltration if the primary domain is blocked. The extensions were removed from Open VSX by August 3, 2026; the disclosure follows a separate npm supply chain campaign, ChainDrop, which compromised 450 packages with a Shai-Hulud worm variant.

The Hacker News · 15d agoMalware

Google’s Early Access is creating a blind spot for malicious apps

Bitdefender found thousands of Google Play Early Access apps with deceptive behavior, including ad-fraud-capable utilities requesting excessive permissions on Android devices.

Bitdefender Labs analyzed Google Play apps installed by its users and identified thousands of Early Access applications that appeared deceptive, including fake casino and reward games, misleading utilities, and apps using third-party trademarks, many promoted via social ads with AI deepfakes. Early Access apps cannot receive public reviews, removing a key warning signal users normally rely on. Some apps requested unusual permissions, such as a QR scanner seeking to replace the device launcher, which could enable hidden web views that click ads and potentially display fake login screens or capture two-factor codes. Bitdefender recommends Android Enterprise Work Profiles and notes Google Workspace admins can disable Early Access apps for their organization.

CSO Onlineupdated · 5d agofirst · 5d agoMalware 6 sources