The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
ID: d7b364ef-f7fd-577f-8f38-81c38b0a8b6e
STIX ID: report--d7b364ef-f7fd-577f-8f38-81c38b0a8b6e
Feed Name: securityonline.info
Researchers at Socket are tracking the GlassWorm campaign: a sophisticated cyber-espionage operation that publishes 'sleeper' impersonation extensions to IDE marketplaces (Open VSX, VS Code, Cursor, Windsurf). The campaign comprises 73 cloned extensions (at least six weaponized), leverages native .node binaries and heavy JavaScript obfuscation to retrieve payloads from GitHub releases, and uses recurring repository naming patterns to hide malicious updates and evade static detection—turning trusted developer tools into malware delivery mechanisms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
