GlassWorm Infiltrates VSX Extensions With 22,000+ Downloads to Target Developers
ID: b25faf06-097e-5167-bde6-2eff9042ba78
STIX ID: report--b25faf06-097e-5167-bde6-2eff9042ba78
Feed Name: GBHackers
**Executive summary:** On 2026-01-30 four long-standing Open VSX extensions in the `oorzc` namespace received malicious updates embedding the GlassWorm staged loader; the loader decrypts and executes a payload, geofences out Russian locales, resolves C2 pointers via Solana transaction memos, and deploys a macOS-focused Node.js infostealer that harvests developer secrets (SSH keys, ~/.aws), npm/GitHub tokens, browser and crypto-wallet data, and exfiltrates archives to hardcoded IP endpoints — the incident appears to stem from suspected compromise of the publisher's credentials and resulted in over 22,000 combined downloads before removal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
