logo

GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks

ID: 7c0448ae-550d-5cb8-99fe-50628e1b5bb4

STIX ID: report--7c0448ae-550d-5cb8-99fe-50628e1b5bb4

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ddos

...
...

GlassWorm is conducting a supply-chain campaign in the Open VSX extension marketplace by abusing Extension Packs and Dependencies to convert benign-looking extensions into delivery vehicles for an obfuscated RCE backdoor. The campaign uses staged loaders, Russian locale/time geofencing to avoid analysis, and Solana transaction memos as covert C2 ‘dead drops’; identified malicious packages include otoboss.autoimport-extension, federicanc.dotenv-syntax-highlighting, and aadarkcode.one-dark-material. Recommended actions include immediate removal of identified extensions, full compromise analysis, auditing extension dependencies, and monitoring the extension host for heavy obfuscation or runtime eval activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.