Related Threat Clusters
-
Supply Chain Attack Targets Checkmarx KICS Tool via Docker and VSCode Extensions
Hackers have compromised Docker images and VSCode extensions for the Checkmarx KICS analysis tool, which is used to identify security vulnerabilities in source code. The attack involved a trojanized KICS Docker image…
2 articles · Updated April 23, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
GlassWorm Malware Campaign Targets OpenVSX with 73 Malicious Extensions
A resurgence of the GlassWorm malware campaign has been identified, targeting the OpenVSX ecosystem with 73 'sleeper' extensions that become malicious after updates. Six of these extensions have already been activated…
8 articles · Updated April 27, 2026 -
Checkmarx Data Leak Linked to Supply-Chain Attack by TeamPCP
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
12 articles · Updated April 27, 2026 -
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
30 articles · Updated May 27, 2026 -
Malicious fast-draft Open VSX Extension Distributes RAT and Infostealer
The KhangNghiem/fast-draft extension on Open VSX was found to contain multiple malicious releases that deploy a remote access trojan (RAT) and an infostealer. Versions 0.10.89, 0.10.105, 0.10.106, and 0.10.112 were…
3 articles · Updated March 19, 2026 -
77 Counterfeit Open VSX Extensions Harvest Developer Data
Between July 26 and August 1, 2026, 77 counterfeit extensions were discovered on the Open VSX marketplace, impersonating legitimate tools and harvesting sensitive developer information. These extensions, linked to a…
10 articles · Updated August 4, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
Critical Vulnerability in Open VSX Allows Malicious Extensions to Bypass Security
Open VSX, the extension marketplace for VS Code forks like Cursor and Windsurf, has addressed a critical vulnerability known as 'Open Sesame' in its pre-publish scanning pipeline. This flaw allowed malicious extensions…
2 articles · Updated March 30, 2026 -
Analysis of GlassWorm V2 Malware via Compromised Cursor Extension
A variant of the GlassWorm malware has been identified, distributed through a compromised Cursor extension on Open VSX. The attack utilizes a sophisticated infection chain and a resilient command-and-control (C2)…
2 articles · Updated March 13, 2026
Recent Intelligence Reports
- Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential — Gbhackers · August 10, 2026
- New research — www.manifold.security · August 6, 2026
- Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces — Gbhackers · August 5, 2026
- 77 Open VSX extensions found harvesting developer info — Bleepingcomputer · August 4, 2026
- CrowdStrike and Google shut down glassworm malware network targeting software developers — Firstpost · May 27, 2026
- Coordinated operation takes down Glassworm botnet — Cybersecuritydive · May 27, 2026
- GitHub Breached via VS Code Extension — Aikido.Dev · May 20, 2026
- Official CheckMarx Jenkins package compromised with infostealer — Bleepingcomputer · May 11, 2026