logo

GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers

ID: 6ac83491-36fc-54ec-9b50-60fc8c73807e

STIX ID: report--6ac83491-36fc-54ec-9b50-60fc8c73807e

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers have identified a significant escalation in the GlassWorm campaign: attackers are abusing Open VSX extension relationships (extensionPack/extensionDependencies) and invisible Unicode obfuscation to turn benign-looking VS Code extensions and upstream packages into transitive delivery vehicles for a credential/secret- and crypto-wallet-stealing loader that uses Solana transactions for resilient C2 resolution; the activity spans dozens of malicious Open VSX extensions, many GitHub repositories, and multiple npm packages, and employs Remote Dynamic Dependencies to retain remote control of payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.