logo

GlassWorm malware returns on OpenVSX with 3 new VSCode extensions

ID: 073254e5-8fa2-5883-ae84-34dc7b7743fe

STIX ID: report--073254e5-8fa2-5883-ae84-34dc7b7743fe

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-11-08

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

GlassWorm is an active supply-chain malware campaign distributing malicious VS Code/OpenVSX extensions (recently three new OpenVSX extensions with ~10,000+ downloads) that use invisible Unicode obfuscation and Solana transactions to retrieve payloads designed to steal developer account credentials and cryptocurrency wallet data; Koi Security accessed an attacker server revealing global victims (about 60 identified so far) and Russian-speaking operators using the RedExt C2 framework.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.