logo

New GlassWorm malware wave targets Macs with trojanized crypto wallets

ID: adb3e76b-6e9d-52a7-beb4-442482141ae8

STIX ID: report--adb3e76b-6e9d-52a7-beb4-442482141ae8

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GlassWorm's fourth wave targets macOS developers by publishing malicious VSCode/OpenVSX extensions that unpack an AES-256-CBC encrypted JavaScript payload which executes after a delay via AppleScript, persists using LaunchAgents, communicates with a Solana-based C2, and steals developer credentials, browser crypto extension data, Keychain passwords, and attempts to replace hardware wallet apps with trojanized versions; three malicious extensions were identified (over 33,000 reported installs) and users are advised to remove the extensions, reset credentials, revoke tokens, and check or reinstall affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.