The GlassWorm supply-chain attack has recently expanded, with researchers identifying 72 additional malicious extensions on the Open VSX Registry as of March 2026. This campaign targets developers by abusing trusted extension features to deliver malware through legitimate-looking updates.
Key Characteristics of the GlassWorm Campaign
- Abuse of Extension Dependencies: Attackers use extensionPack and extensionDependencies to turn previously standalone, benign extensions into vehicles for malicious code.
- Invisible Code Injection: The malware utilizes invisible Unicode variation selectors and Private Use Area (PUA) characters, making the malicious code invisible to human reviewers and standard diff tools.
- Resilient Infrastructure: It employs a triple-layered command-and-control (C2) system using the Solana blockchain (via transaction memos), Google Calendar events as fallbacks, and direct IP connections.
- Self-Propagating Worm Behavior: Once a workstation is infected, the malware harvests GitHub, npm, and Open VSX credentials to compromise more extensions and packages accessible by the victim.
Targeted Data and Payloads
- Infostealer Capabilities: GlassWorm steals macOS credentials, browser cookies, and session data.
- Financial Theft: It targets over 49 different cryptocurrency wallet extensions (e.g., Coinbase, MetaMask, Phantom) to drain funds.
- Remote Access (ZOMBI RAT): The final stage installs a Hidden Virtual Network Computing (HVNC) client and a SOCKS proxy, turning the developer machine into a node for a criminal infrastructure.
Impact and History
- Timeline: First discovered in October 2025, the campaign has seen multiple waves, including a significant escalation in January 2026 involving hijacked legitimate accounts (like “oorzc”).
- Mimicked Tools: Malicious extensions often mimic widely used utilities like linters, formatters, and AI-powered coding assistants such as Clade Code or Google Antigravity.
- Evasion: The malware often includes checks to avoid executing on systems with Russian locales.
Recommended Actions for Developers
According to security experts at Socket and Veracode, developers should:
- Audit Extensions: Manually review all installed extensions, specifically checking for unverified publishers or sudden updates to inactive projects.
- Disable Auto-Updates: Consider disabling automatic extension updates to allow for manual verification.
- Rotate Credentials: Immediately change GitHub, npm, and Open VSX tokens if any suspicious activity is detected.
- Monitor Network Logs: Watch for unusual outbound connections to Solana RPC nodes or unknown IP addresses.