logo

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm

ID: cf79480d-cb84-5bc5-bd4b-1e834ef25f33

STIX ID: report--cf79480d-cb84-5bc5-bd4b-1e834ef25f33

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Supply-chain attack on Open VSX: threat actor pushed malicious updates for four oorzc extensions that embedded the GlassWorm loader to macOS users. The loader decrypts and runs at runtime, uses EtherHiding and Solana memos for C2/staging rotation, and exfiltrates browser credentials, crypto wallets, iCloud Keychain, developer secrets (e.g., ~/.aws, ~/.ssh) and user documents; the poisoned releases had ~22,000 cumulative downloads and were later removed, though auto-update/uninstall behavior complicates remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.