New GlassWorm attack targets macOS via compromised OpenVSX extensions
ID: 993a7fb5-1f9e-5c9a-93d0-ed2cb7abc57f
STIX ID: report--993a7fb5-1f9e-5c9a-93d0-ed2cb7abc57f
Feed Name: Bleeping Computer
A GlassWorm supply-chain campaign trojanized four OpenVSX extensions (totaling ~22,000 downloads) via a compromised developer account to deliver a macOS-focused information stealer. The malware persists via a LaunchAgent, harvests browser and wallet data, keychain entries, developer secrets, and files, supports VNC/SOCKS remote access, pulls instructions from Solana memos, excludes Russian-locale systems, and exfiltrates collected data to 45.32.150.251; malicious releases were removed after reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
