Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm
ID: cf79480d-cb84-5bc5-bd4b-1e834ef25f33
STIX ID: report--cf79480d-cb84-5bc5-bd4b-1e834ef25f33
Feed Name: The Hacker News
Supply-chain attack on Open VSX: threat actor pushed malicious updates for four oorzc extensions that embedded the GlassWorm loader to macOS users. The loader decrypts and runs at runtime, uses EtherHiding and Solana memos for C2/staging rotation, and exfiltrates browser credentials, crypto wallets, iCloud Keychain, developer secrets (e.g., ~/.aws, ~/.ssh) and user documents; the poisoned releases had ~22,000 cumulative downloads and were later removed, though auto-update/uninstall behavior complicates remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
