GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers
GlassWorm has been identified as a threat to developers utilizing the Open VSX Registry, where it has compromised popular VSX extensions to distribute malware.
GlassWorm has been identified as a threat to developers utilizing the Open VSX Registry, where it has compromised popular VSX extensions to distribute malware.
Threat actors compromised a trusted publisher account, releasing updates disguised as routine that contained a staged loader. These malicious extensions, downloaded over 22,000 times, were utilized in tasks such as file synchronization and CSS workflows, transforming them into potential attack vectors.
Socket.dev analysts identified this as a developer-compromise supply chain attack, potentially initiated by leaked publishing tokens or unauthorized access to the oorzc publisher account. The malicious versions jeopardized developers who installed or updated the affected extensions, unknowingly downloading the GlassWorm loader.
The Open VSX security team confirmed the breach, removed the compromised releases, and revoked the publisher's tokens. However, the duration of exposure has raised concerns about credential theft and downstream abuse.
Threat actors compromised a trusted publisher account, releasing updates disguised as routine that contained a staged loader.
The attack leverages existing, legitimate extensions, focusing primarily on macOS systems. The malware targets browser data, cryptocurrency wallets, SSH keys, AWS credentials, and GitHub/npm tokens. The staged execution chain involves decrypting and executing an embedded payload, which profiles the host and retrieves further instructions from Solana transaction memos. A final stage collects credentials and documents, exfiltrating them to attacker-controlled infrastructure. A LaunchAgent entry ensures persistence across reboots.
This escalation from simple theft to deep supply chain access signifies that a single compromised device could serve as an entry point into broader cloud environments and CI pipelines.
Developers are advised to remain vigilant and verify the integrity of their development tools to prevent such threats.
Based on reporting by Cyber Security News.
