logo

The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign

ID: d7b364ef-f7fd-577f-8f38-81c38b0a8b6e

STIX ID: report--d7b364ef-f7fd-577f-8f38-81c38b0a8b6e

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Ddos

...
...

Researchers at Socket are tracking the GlassWorm campaign: a sophisticated cyber-espionage operation that publishes 'sleeper' impersonation extensions to IDE marketplaces (Open VSX, VS Code, Cursor, Windsurf). The campaign comprises 73 cloned extensions (at least six weaponized), leverages native .node binaries and heavy JavaScript obfuscation to retrieve payloads from GitHub releases, and uses recurring repository naming patterns to hide malicious updates and evade static detection—turning trusted developer tools into malware delivery mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.