
The GlassWorm supply-chain attack is back with a large, synchronized assault affecting many packages, repositories, and add-ons on GitHub, npm, and VSCode/OpenVSX.
Researchers from Aikido, Socket, Step Security, and the OpenSourceMalware collective have found 433 infected components this month linked to GlassWorm.
The use of the same Solana blockchain address for command-and-control (C2), similar malicious code, and shared infrastructure suggests that a single attacker is behind the GlassWorm campaigns affecting various open-source repositories.
GlassWorm was first spotted last October. The attackers used hidden Unicode characters to conceal malicious code designed to steal cryptocurrency wallet data and developer login information.
The attack continued with several phases and spread to Microsoft’s Visual Studio Code marketplace and the OpenVSX registry used by other IDEs, as discovered by Secure Annex’s John Tuckner.
macOS users were also targeted with infected Trezor and Ledger clients and later, developers through compromised OpenVSX extensions.
However, this recent GlassWorm attack is much larger and has expanded to:
The initial breach occurs on GitHub where accounts are hijacked to force-push infected commits.
Then, malicious packages and extensions are published on npm and VSCode/OpenVSX. These packages include obscured code (invisible Unicode characters) to avoid being detected.
Across all platforms, the Solana blockchain is checked every five seconds for new instructions. Step Security reported that 50 new transactions occurred between November 27, 2025, and March 13, 2026, primarily to update the payload URL.
The instructions were embedded as memos in the transactions, leading to the download of the Node.js runtime and execution of a JavaScript-based data-stealing program.
The malware focuses on cryptocurrency wallet information, login credentials, access tokens, SSH keys, and developer environment details.
Analyzing code comments suggests that Russian-speaking threat actors are behind GlassWorm. The malware also avoids running if the system is set to the Russian locale. However, this information is not sufficient for confident attribution.
Step Security is advising developers who install Python packages directly from GitHub or run cloned repositories, to check their code for âlzcdrtfxyqiplpd,â a variable that indicates the presence of GlassWorm malware.
They also recommend that developers inspect their systems for the ~/init.json file which is used for persistence, and look for unexpected Node.js installations in the home directory (e.g., ~/node-v22*).
Additionally, developers should also check recently cloned projects for suspicious i.js files and check Git commit histories for anything unusual, such as commits where the committer date is much later than the original author date.
#400 #across #and #code #github #glassworm #has #infected #malicious #news #npm #openvsx. #over #repositories #software #vscode, — News
© Bulletproof Servers. All rights reserved.