Glassworm Malware Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 2, 2025
Last Seen
February 7, 2026

Glassworm Malware Campaign is a threat campaign tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity February 7, 2026.

Overview

Glassworm Malware Campaign is a threat actor operation that injects malicious payloads into IDE extension ecosystems, specifically OpenVSX and the Microsoft Visual Studio Marketplace. It has recently released 24 new packages across these platforms, signaling an ongoing cross-platform supply-chain style campaign aimed at developers. The campaign is significant due to its misuse of widely used development tooling to compromise developer environments and enable potential backdoors or data exfiltration.

Related Threat Clusters

Recent Intelligence Reports

  • Dangerous new malware targets macOS devices via OpenVSX extensions — Msn · February 7, 2026
  • Glassworm Malware Hits OpenVSX and Microsoft Visual Studio Platforms with 24 New Packages — Cybersecuritynews · December 2, 2025

CVSS v3.1 Breakdown