logo

Glassworm malware returns in third wave of malicious VS Code packages

ID: 3a778346-41c7-56b6-9236-1bdb16f25186

STIX ID: report--3a778346-41c7-56b6-9236-1bdb16f25186

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-12-01

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Executive summary:** The Glassworm campaign is a supply-chain malware campaign distributing malicious VS Code extensions on the Microsoft Visual Studio Marketplace and OpenVSX; once installed the extensions steal GitHub/npm/OpenVSX credentials and wallet data, deploy SOCKS proxies and HVNC for remote access, and use techniques like invisible Unicode obfuscation, Rust-based implants, and fake download inflation to evade detection and appear legitimate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.