• News/
  • https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/

GlassWorm malware returns on OpenVSX with 3 new VSCode extensions

BleepingComputer
·
Bill Toulas
·
Published Nov 8, 2025
·
Updated

The GlassWorm malware campaign, which impacted the OpenVSX and Visual Studio Code marketplaces last month, has returned with three new VSCode extensions that have already been downloaded over 10,000 times. GlassWorm is a campaign and malware that leverages Solana transactions to fetch a payload targeting GitHub, NPM, and OpenVSX account credentials, as well as cryptocurrency wallet data from 49 extensions. The malware uses invisible Unicode characters that render as blanks, but execute as JavaScript to facilitate malicious actions. It first appeared via 12 extensions on Microsoft's VS Code and OpenVSX marketplaces, which were downloaded 35,800 times. However, it is believed that the number of downloads was inflated by the threat actor, making the full impact of the campaign unknown. In response to this compromise, Open VSX rotated access tokens for an undisclosed number of accounts breached by GlassWorm, implemented security enhancements, and marked the incident as closed. According to Koi Security, which has been tracking the campaign, the attacker has now returned to OpenVSX, using the same infrastructure but with updated command-and-control (C2) endpoints and Solana transactions. The three OpenVSX extensions carrying the GlassWorm payload are: Koi Security says all three extensions use the same invisible Unicode character obfuscation trick as the original files. Evidently, this remains effective at bypassing OpenVSX's newly introduced defenses. As Aikido reported earlier,...

Read full article

Affected Software

2 affected components
Microsoft Visual Studio Code
OpenVSX OpenVSX
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the resurgence of the GlassWorm malware campaign with the introduction of new malicious VSCode extensions.

2

What security implications are discussed in the article?

The article highlights the risks of downloading malicious VSCode extensions that can compromise user security.

3

What products or software are affected by the GlassWorm malware?

The affected software includes Visual Studio Code and OpenVSX.

4

How many times have the new VSCode extensions been downloaded?

The new VSCode extensions linked to the GlassWorm malware have been downloaded over 10,000 times.

5

What platforms were targeted by the GlassWorm malware campaign mentioned in the article?

The GlassWorm malware targeted both the OpenVSX and Visual Studio Code marketplaces.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203