logo

GlassWorm Campaign Expands Through Malicious Open VSX Extensions

ID: 15a655d7-5346-5aae-b22e-7c2056654c54

STIX ID: report--15a655d7-5346-5aae-b22e-7c2056654c54

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

GlassWorm has expanded its operations by abusing Open VSX extension manifest fields (extensionPack and extensionDependencies) to deliver malware transitively through seemingly benign developer extensions; researchers identified at least 72 additional malicious extensions, live examples still active, and associated infrastructure (Solana wallets, C2 IPs, cryptographic artifacts) while noting changes in obfuscation and delivery techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.