Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New GlassWorm Using Invisible Code Hits Attacking VS Code Extensions on OpenVSX Marketplace

In October 2025, a significant cybersecurity threat emerged with the detection of GlassWorm, a self-propagating malware campaign affecting VS Code extensions on the OpenVSX Marketplace. This development underscores the growing challenges in securing…

In October 2025, a significant cybersecurity threat emerged with the detection of GlassWorm, a self-propagating malware campaign affecting VS Code extensions on the OpenVSX Marketplace. This development underscores the growing challenges in securing supply chain systems within developer ecosystems.

Reports indicate that over 35,800 installations have been compromised, with ongoing risks due to active malicious extensions. The attack's impact includes credential theft and deeper infiltration into developer systems.

The campaign was initially identified by Koi researchers who noted unusual behavior in the "CodeJoy" extension following its 1.8.3 update. Although the extension initially passed visual code reviews, Koi’s risk engine detected anomalous network connections and credential access.

The infection mechanism was novel, utilizing invisible Unicode characters to embed malicious code within otherwise legitimate JavaScript source files. This allowed the malware to evade detection by most static analysis tools.

This development underscores the growing challenges in securing supply chain systems within developer ecosystems.
Adam Foster · Thehackingpost

The worm is designed to harvest secrets from npm, GitHub, and OpenVSX, as well as target multiple cryptocurrency wallet extensions. It uses the stolen credentials to further propagate, ultimately creating a self-sustaining cycle. Compromised devices can then be used as proxy nodes or platforms for remote attacks.

Analysts have confirmed that the attackers have established a resilient command-and-control infrastructure using the Solana blockchain. The use of blockchain for payload distribution, along with additional C2 mechanisms such as Google Calendar events and direct IP endpoints, complicates mitigation efforts.

A distinctive feature of the GlassWorm operation is its use of Unicode "variation selector" exploits. These non-rendering characters allow malicious code to remain hidden from visual editors and code review platforms while being executed by JavaScript interpreters.

Advertisement

To address this threat, it is crucial for development teams to update their code inspection and continuous integration processes to detect non-standard Unicode characters. Specialized tools capable of byte-wise analysis are recommended to uncover hidden payloads.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories