73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign
ID: b0270078-4814-5e0a-80f6-8771ee44bbe2
STIX ID: report--b0270078-4814-5e0a-80f6-8771ee44bbe2
Feed Name: cybersecurityNews.com
GlassWorm operators published 73 ‘sleeper’ extensions to the Open VSX marketplace (identified April 2026) that initially appear benign and later receive updates to install malicious .vsix payloads; delivery methods include hidden native binaries and heavily obfuscated JavaScript that fetches payloads from GitHub. The campaign has activated at least six extensions and includes observable indicators (SHA256 hashes, a malicious GitHub repo, and confirmed extension names) that defenders should monitor and use to validate publisher namespaces and download counts before installation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
