Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users
ID: 6a8acfd9-2107-52aa-8f14-3d4861415892
STIX ID: report--6a8acfd9-2107-52aa-8f14-3d4861415892
Feed Name: cybersecurityNews.com
Threat Score
GlassWorm’s fourth wave targets macOS through malicious VS Code extensions on the Open VSX marketplace, leveraging AES-256-CBC encrypted JavaScript payloads, a 15-minute delay to evade sandboxes, and a Solana blockchain-based decentralized C2; it includes macOS-specific theft (Keychain access), LaunchAgent persistence, and code to trojanize hardware wallet apps, with infrastructure and IP indicators linked to the same actor and over 50,000 downloads reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
