Skip to main content
Security

GlassWorm supply chain attack hits OpenVSX with 73 malicious extensions

GlassWorm supply chain attack hits OpenVSX with 73 malicious extensions Image: Primary
A new wave of the GlassWorm campaign is targeting the OpenVSX ecosystem with 73 extensions that turn malicious after an update, according to researchers at application security company Socket. Six of the extensions have been activated and deliver malware, while researchers assess with high confidence that the rest are dormant or suspicious. When initially uploaded, the extensions are benign but deliver the payload at a later stage. GlassWorm is an ongoing supply chain attack campaign first observed in October, initially using invisible Unicode characters to hide malicious code that steals cryptocurrency wallets and developer credentials. It has since expanded across multiple ecosystems, including GitHub repositories, npm packages, and both the Visual Studio Code Marketplace and OpenVSX. The attackers have also been observed targeting macOS users with trojanized crypto wallet clients. A recent wave in mid-March 2026 showed significant scale, affecting hundreds of repositories and dozens of extensions. The latest wave suggests the attacker is changing strategy by submitting innocuous extensions to a single ecosystem and introducing malicious functionality through updates. Previously, these attacks were aimed at stealing cryptocurrency wallet data, credentials, access tokens, SSH keys, and developer environment data. Socket has published the full list of the 73 extensions believed to be part of the latest wave and recommends that developers who installed any of them rotate all secrets and clean their environment.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Chrome 153 fixes actively exploited V8 flaw

Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...

Security
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...

Security
Security

Vishing campaign targets executives for Microsoft 365 data theft

Arctic Wolf has described a data-theft and extortion cluster targeting Microsoft 365 and other SaaS accounts through fraudulent IT-help-desk calls, adversary-in-the-middle login pages and residential-proxy session replay. The acti...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...