Bleepingcomputer
GlassWorm Malware Resurfaces in Open VSX Extensions Following Token Leak
First seen 1 Dec 2025, 20:43 UTC
•



+5
•30.3
Export
Article Content
Browse articles
The Open VSX registry faced a supply chain attack after access tokens were leaked, allowing threat actors to publish malicious extensions. The GlassWorm malware campaign has returned with new extensions targeting developers' credentials and cryptocurrency wallets, leveraging obfuscation techniques to evade detection. Over 10,000 downloads of the new malicious extensions have been reported.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Glassworm Malware Targets React Native npm Packages in Supply Chain Attack
GlassWorm Malware Campaign Targets OpenVSX with 73 Malicious Extensions
Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
Armored Likho Expands Cyber-Espionage with New Rust Toolkit