GlassWorm malware returns on OpenVSX with 3 new VSCode extensions
ID: 073254e5-8fa2-5883-ae84-34dc7b7743fe
STIX ID: report--073254e5-8fa2-5883-ae84-34dc7b7743fe
Feed Name: Bleeping Computer
GlassWorm is an active supply-chain malware campaign distributing malicious VS Code/OpenVSX extensions (recently three new OpenVSX extensions with ~10,000+ downloads) that use invisible Unicode obfuscation and Solana transactions to retrieve payloads designed to steal developer account credentials and cryptocurrency wallet data; Koi Security accessed an attacker server revealing global victims (about 60 identified so far) and Russian-speaking operators using the RedExt C2 framework.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
