GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach
ID: c8e36c53-d8ec-5cfd-9d7a-fd9eeaa6e3e6
STIX ID: report--c8e36c53-d8ec-5cfd-9d7a-fd9eeaa6e3e6
Feed Name: cybersecurityNews.com
GlassWorm operators published at least 72 malicious Open VSX extensions that initially present as benign but later modify their manifests to add `extensionPack`/`extensionDependencies` pointing to a hidden loader, enabling transitive supply-chain infections of developer workstations; the malware aims to steal credentials and environment secrets and uses advanced obfuscation, remote key retrieval, Solana transaction memos, and geofencing — defenders should audit extension update histories, review full install/update chains, hunt for provided IoCs (Solana memo lookups, IPs, wallet address), and block/remove known GlassWorm packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
