Glassworm Malware Campaign is a threat campaign tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity February 7, 2026.
Glassworm Malware Campaign is a threat actor operation that injects malicious payloads into IDE extension ecosystems, specifically OpenVSX and the Microsoft Visual Studio Marketplace. It has recently released 24 new packages across these platforms, signaling an ongoing cross-platform supply-chain style campaign aimed at developers. The campaign is significant due to its misuse of widely used development tooling to compromise developer environments and enable potential backdoors or data exfiltration.
A sophisticated malware campaign has compromised the Open VSX extension marketplace, affecting over 5,000 developer workstations. The malicious package masqueraded as a legitimate Angular Language Service extension,…
The Open VSX registry faced a supply chain attack after access tokens were leaked, allowing threat actors to publish malicious extensions. The GlassWorm malware campaign has returned with new extensions targeting…