logo

GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions

ID: 2d7a46fa-258e-534b-97d8-fd0e8440bb3d

STIX ID: report--2d7a46fa-258e-534b-97d8-fd0e8440bb3d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Bill Toulas

...
...

GlassWorm operators pushed 73 'sleeper' extensions to the OpenVSX marketplace that appear benign on upload but later activate to fetch and install malicious payloads via secondary VSIX packages, platform-specific .node modules, or obfuscated JavaScript; researchers at Socket found six active malicious extensions and classify the remainder as dormant or suspicious, advising developers to rotate secrets and clean affected environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.