logo

Self-spreading GlassWorm malware hits OpenVSX, VS Code registries

ID: e4166702-6285-5f93-bc2a-6f61aa3287cc

STIX ID: report--e4166702-6285-5f93-bc2a-6f61aa3287cc

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-10-20

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

GlassWorm is a self-spreading supply-chain malware campaign that compromised multiple OpenVSX and VS Code extensions (researchers estimate ~35,800 installs). The malware hides code using invisible Unicode characters, steals GitHub/npm/OpenVSX credentials and cryptocurrency wallet data, deploys SOCKS proxies and HVNC for remote access, and uses Solana blockchain transactions (with base64 payload links), BitTorrent DHT, and Google Calendar events as resilient command-and-control and payload delivery mechanisms; multiple infected extensions and an IP-based delivery fallback were observed and some C2/payload servers remain active.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.