Socprime GlassWorm Campaign Targets Developers with Malicious VS Code Extensions
Article Content
- •Malicious VS Code extensions linked to GlassWorm have over 8,000 installs.
- •Extensions use obfuscated JavaScript loaders to fetch additional payloads.
- •Organizations should review and monitor installed extensions for security.
A cluster of malicious Visual Studio Code extensions linked to the GlassWorm threat actor was uncovered, affecting thousands of developers. These extensions, disguised as color themes, contain obfuscated JavaScript loaders that can retrieve secondary payloads. The Socket Threat Research team identified two confirmed malicious extensions and several high-risk, cluster-linked identities through Git history analysis. The malicious extensions, including Coca-Cola Christmas and Aurora Borealis Studio Theme, have accumulated over 8,000 installs on the Visual Studio Marketplace. The malware uses techniques such as AES-256-CBC decryption and Solana blockchain transaction memos to communicate with command and control infrastructure. Organizations are advised to review their installed extensions, particularly those from the Visual Studio Marketplace and Open VSX. Immediate isolation of affected hosts is recommended if malicious activity is detected. The campaign exploits the software supply chain to target developers and steal sensitive data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
Which extensions are confirmed malicious?
What should organizations do to protect themselves?
How widespread is the impact of this campaign?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…