logo

73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign

ID: b0270078-4814-5e0a-80f6-8771ee44bbe2

STIX ID: report--b0270078-4814-5e0a-80f6-8771ee44bbe2

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-26

Date Updated: 2026-04-26

Author: Abinaya

...
...

GlassWorm operators published 73 ‘sleeper’ extensions to the Open VSX marketplace (identified April 2026) that initially appear benign and later receive updates to install malicious .vsix payloads; delivery methods include hidden native binaries and heavily obfuscated JavaScript that fetches payloads from GitHub. The campaign has activated at least six extensions and includes observable indicators (SHA256 hashes, a malicious GitHub repo, and confirmed extension names) that defenders should monitor and use to validate publisher namespaces and download counts before installation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.