logo

Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain

ID: 52447400-9571-5521-a65a-00f3bb783825

STIX ID: report--52447400-9571-5521-a65a-00f3bb783825

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Elizabeth Montalbano

...
...

Researchers from Socket describe a renewed GlassWorm campaign that has published a cluster of ~73 'sleeper' VS Code/Open VSX extensions which initially appear benign but can later fetch or execute malicious payloads (including bundled native installers) to deploy self‑propagating infostealers that steal developer secrets and poison the software supply chain. Attackers clone legitimate listings to trick developers, at least six extensions have already activated malicious payloads, IoCs are provided, and the report urges continuous monitoring, publisher verification, and audit of extension updates to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.