Redhotcyber Malware Campaign Targets Open VSX Extension with 5,066 Downloads
Article Content
Browse articles
A sophisticated malware campaign has compromised the Open VSX extension marketplace, affecting over 5,000 developer workstations. The malicious package masqueraded as a legitimate Angular Language Service extension, embedding encrypted malware that activates upon opening HTML or TypeScript files. The attack utilized typosquatting and steganography techniques to evade detection.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (20)
Following this threat?
Track Glassworm and Open VSX Extension Marketplace in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PEEP Chrome Extension Turns Browsers Into Remote Access Tools Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be installed, allowing it to bypass Web Store checks and inject itself directly into Chrome and Edge profiles.…
Armored Likho Expands Cyber-Espionage with New Rust Toolkit In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and educational institutions. The attackers employed a fraudulent donation-service application as the initial…