GlassWorm Malware Evolves to Hide in Dependencies
ID: 30c2ec49-cedf-5a30-8e99-1e60a0f45df5
STIX ID: report--30c2ec49-cedf-5a30-8e99-1e60a0f45df5
Feed Name: Dark Reading
Socket's research reveals an active GlassWorm campaign targeting Open VSX developer extensions: attackers are using transitive dependencies (extensionPack/extensionDependencies), staged JavaScript loaders, Solana memo lookups for C2, geofencing, in-memory execution, and rotating infrastructure to steal credentials and other sensitive developer data and propagate poisoned packages downstream. Defenders are advised to audit extension manifest changes and install/update chains and hunt for staged loaders, Solana memo lookups, and Russian gating as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
