logo

GlassWorm Spreads via 72 Malicious Open VSX Extensions Hidden in Transitive Dependencies

ID: 2edeeee3-de2e-5a0f-8016-c232788b0cde

STIX ID: report--2edeeee3-de2e-5a0f-8016-c232788b0cde

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-14

Date Updated: 2026-04-22

Author: Divya

...
...

The report describes the GlassWorm campaign which increasingly targets developers by publishing clean Open VSX extensions that later pull malicious extensions via extensionPack/extensionDependencies, enabling stealthy transitive delivery of loaders that steal credentials, tokens, and environment secrets. Researchers identified at least 72 malicious Open VSX extensions, noted infrastructure updates (Solana wallet rotation, C2 IPs), stronger obfuscation, and use of externalized decryption keys; the report recommends auditing extension histories, monitoring install chains and known IoCs, and securing developer endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.