Open VSX Hijacked: “GlassWorm” Malware Poisons VS Code Extensions
ID: 43127b8a-f2ae-5e7d-ba7a-9d737775dfea
STIX ID: report--43127b8a-f2ae-5e7d-ba7a-9d737775dfea
Feed Name: securityonline.info
A supply-chain campaign beginning 30 January 2026 compromised a trusted Open VSX publisher account to push malicious updates (GlassWorm) to four popular VS Code extensions (combined ~22,000 downloads). The multi-stage loader targets macOS developer environments to exfiltrate credentials (~/.aws, ~/.ssh), cryptocurrency wallet files, browser and keychain data, and FortiClient VPN configs, and uses Solana transaction memos as a covert C2 dead-drop; Open VSX disabled the publisher tokens and removed the malicious versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
