Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GlassWorm Malware Turns VS Code Extensions into an Attack Vector Against macOS

GlassWorm, a self-propagating malware, has evolved and now targets macOS. Initially identified in October via VS Code extensions, it now has 50,000 downloads and a fully functional infrastructure.

GlassWorm, a self-propagating malware, has evolved and now targets macOS. Initially identified in October via VS Code extensions, it now has 50,000 downloads and a fully functional infrastructure.

Security experts have pinpointed three malicious extensions in the Open VSX marketplace linked to the actor by shared command-and-control infrastructure, specifically the IP address 45.32.151.157.

This development marks a significant escalation, utilizing AES-256-CBC encrypted payloads in compiled JavaScript rather than previous Unicode obfuscation techniques. The encryption employs a hardcoded key shared across the malicious extensions, indicating a single coordinated threat actor.

The malware includes a 15-minute execution delay to evade automated sandbox environments that timeout after five minutes, effectively bypassing initial security scans upon installation.

The latest wave targets macOS, diverging from previous Windows-only attacks. This shift is strategic, as many developers in cryptocurrency and startup ecosystems use Apple devices. The macOS payload uses AppleScript for execution, LaunchAgents for persistence, and directly targets the Keychain database.

GlassWorm, a self-propagating malware, has evolved and now targets macOS.
Benjamin Scott · Thehackingpost

GlassWorm's command-and-control infrastructure continues to evolve. A new Solana wallet address (BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC) has been deployed, supplementing existing wallets. The blockchain-based C2 mechanism uses Solana transaction memos with base64-encoded URLs to update C2 endpoints, making them decentralized and resistant to takedown.

Infrastructure monitoring shows changes between IP addresses 217.69.11.60 and 45.32.151.157, with a new exfiltration server at 45.32.150.251.

The malware's most concerning new capability is targeting hardware wallets like Ledger Live and Trezor Suite by replacing legitimate software with compromised versions.

Advertisement

If successful, this attack could display fake addresses, alter transaction details, capture seed phrases, and intercept device communications, compromising hardware wallet security. The C2 endpoints for these payloads currently return empty files, suggesting preparation stages are ongoing as of Thu, Dec 29, 2025.

GlassWorm includes file-size validation, preventing installations smaller than 1000 bytes, reflecting sophisticated development practices. The malware continues to adapt and evolve in response to security research, maintaining an active and operational threat.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories