logo

New GlassWorm attack targets macOS via compromised OpenVSX extensions

ID: 993a7fb5-1f9e-5c9a-93d0-ed2cb7abc57f

STIX ID: report--993a7fb5-1f9e-5c9a-93d0-ed2cb7abc57f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A GlassWorm supply-chain campaign trojanized four OpenVSX extensions (totaling ~22,000 downloads) via a compromised developer account to deliver a macOS-focused information stealer. The malware persists via a LaunchAgent, harvests browser and wallet data, keychain entries, developer secrets, and files, supports VNC/SOCKS remote access, pulls instructions from Solana memos, excludes Russian-locale systems, and exfiltrates collected data to 45.32.150.251; malicious releases were removed after reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.