logo

GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers

ID: 58e09e3b-7479-5287-b188-cb90d81e8516

STIX ID: report--58e09e3b-7479-5287-b188-cb90d81e8516

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GlassWorm is a supply-chain malware campaign that compromised the oorzc publisher on the Open VSX Registry to push malicious updates to four legitimate extensions (together with over 22,000 downloads). The staged macOS-focused loader profiles victims, avoids Russian locales, retrieves commands via Solana transaction memos, persists using a LaunchAgent, and steals browser data, cryptocurrency wallets, SSH keys and cloud/GitHub/npm credentials before exfiltration; Open VSX later removed the malicious releases and revoked the publisher's tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.