logo

GlassWorm Infiltrates VSX Extensions With 22,000+ Downloads to Target Developers

ID: b25faf06-097e-5167-bde6-2eff9042ba78

STIX ID: report--b25faf06-097e-5167-bde6-2eff9042ba78

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** On 2026-01-30 four long-standing Open VSX extensions in the `oorzc` namespace received malicious updates embedding the GlassWorm staged loader; the loader decrypts and executes a payload, geofences out Russian locales, resolves C2 pointers via Solana transaction memos, and deploys a macOS-focused Node.js infostealer that harvests developer secrets (SSH keys, ~/.aws), npm/GitHub tokens, browser and crypto-wallet data, and exfiltrates archives to hardcoded IP endpoints — the incident appears to stem from suspected compromise of the publisher's credentials and resulted in over 22,000 combined downloads before removal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.