GlassWorm Spreads via 72 Malicious Open VSX Extensions Hidden in Transitive Dependencies
ID: 2edeeee3-de2e-5a0f-8016-c232788b0cde
STIX ID: report--2edeeee3-de2e-5a0f-8016-c232788b0cde
Feed Name: GBHackers
The report describes the GlassWorm campaign which increasingly targets developers by publishing clean Open VSX extensions that later pull malicious extensions via extensionPack/extensionDependencies, enabling stealthy transitive delivery of loaders that steal credentials, tokens, and environment secrets. Researchers identified at least 72 malicious Open VSX extensions, noted infrastructure updates (Solana wallet rotation, C2 IPs), stronger obfuscation, and use of externalized decryption keys; the report recommends auditing extension histories, monitoring install chains and known IoCs, and securing developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
