logo

GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach

ID: c8e36c53-d8ec-5cfd-9d7a-fd9eeaa6e3e6

STIX ID: report--c8e36c53-d8ec-5cfd-9d7a-fd9eeaa6e3e6

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-14

Date Updated: 2026-04-21

Author: Dhivya

...
...

GlassWorm operators published at least 72 malicious Open VSX extensions that initially present as benign but later modify their manifests to add `extensionPack`/`extensionDependencies` pointing to a hidden loader, enabling transitive supply-chain infections of developer workstations; the malware aims to steal credentials and environment secrets and uses advanced obfuscation, remote key retrieval, Solana transaction memos, and geofencing — defenders should audit extension update histories, review full install/update chains, hunt for provided IoCs (Solana memo lookups, IPs, wallet address), and block/remove known GlassWorm packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.