Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach

In a significant development regarding supply chain attacks, the GlassWorm malware campaign has advanced to compromise developer environments by utilizing transitive dependencies.

In a significant development regarding supply chain attacks, the GlassWorm malware campaign has advanced to compromise developer environments by utilizing transitive dependencies.

On Mon, Mar 13, 2026, the Socket Research Team identified at least 72 new malicious Open VSX extensions associated with this campaign.

Threat actors are disguising malware by integrating it through secondary updates after initial trust is established.

This new technique exploits two legitimate extension manifest fields: extensionPack and extensionDependencies . These fields are intended to assist developers in conveniently bundling necessary extensions.

GlassWorm operators initially publish benign extensions to the Open VSX registry. Once developers install these extensions, attackers issue an update to alter the manifest files.

On Mon, Mar 13, 2026, the Socket Research Team identified at least 72 new malicious Open VSX extensions associated with this campaign.
Jonathan Pierce · Thehackingpost

This update introduces an extensionPack or extensionDependencies link to a hidden GlassWorm loader, leading to automatic installation of the malicious dependency by the code editor.

The campaign involves impersonating popular developer utilities and inflating download counts, targeting tools like linters, code formatters, and AI developer assistants.

GlassWorm aims to steal credentials, configuration data, and environment secrets, while employing advanced technical capabilities such as:

Infrastructure rotation: Transitioning Solana wallet infrastructure and adding new command-and-control IP addresses. Advanced obfuscation: Utilizing RC4, base64, and string-array obfuscation techniques. Remote decryption: Retrieving decryption keys dynamically from attacker-controlled HTTP response headers. Execution guardrails: Employing staged JavaScript execution and geofencing to evade analysis.

Advertisement

To mitigate these threats, development teams need to enhance their security practices. Initial code reviews of extensions are insufficient.

To protect against transitive GlassWorm infections, implement the following measures:

Audit the version history of installed extensions for new extensionPack or extensionDependencies relationships. Review entire installation and update chains rather than only current extension code. Search for GlassWorm indicators, such as Solana memo lookups or staged loaders. Block and remove known GlassWorm-linked packages and check for exposed environment tokens.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories