Glassworm malware returns in third wave of malicious VS Code packages
ID: 3a778346-41c7-56b6-9236-1bdb16f25186
STIX ID: report--3a778346-41c7-56b6-9236-1bdb16f25186
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** The Glassworm campaign is a supply-chain malware campaign distributing malicious VS Code extensions on the Microsoft Visual Studio Marketplace and OpenVSX; once installed the extensions steal GitHub/npm/OpenVSX credentials and wallet data, deploy SOCKS proxies and HVNC for remote access, and use techniques like invisible Unicode obfuscation, Rust-based implants, and fake download inflation to evade detection and appear legitimate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
