logo

Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users

ID: 6a8acfd9-2107-52aa-8f14-3d4861415892

STIX ID: report--6a8acfd9-2107-52aa-8f14-3d4861415892

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-31

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GlassWorm’s fourth wave targets macOS through malicious VS Code extensions on the Open VSX marketplace, leveraging AES-256-CBC encrypted JavaScript payloads, a 15-minute delay to evade sandboxes, and a Solana blockchain-based decentralized C2; it includes macOS-specific theft (Keychain access), LaunchAgent persistence, and code to trojanize hardware wallet apps, with infrastructure and IP indicators linked to the same actor and over 50,000 downloads reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.