Glassworm returns once again with a third round of VS code attacks

  • Glassworm campaign re-emerges with 24 malicious extensions on OpenVSX and Visual Studio marketplaces
  • Malware steals GitHub, npm, wallet tokens, and deploys HVNC client with SOCKS proxy
  • Targets frameworks like Flutter, React Native, Vue; Microsoft working to harden defenses

Malware is back on the OpenVSX and Microsoft Visual Studio marketplaces, researchers are warning. In mid-September this year, it was reported that cybercriminals were targeting crypto holders and developers by smuggling infostealers into open-source code repositories.

The Visual Studio Marketplace and the Open VSX Registry are both platforms for distributing extensions, with the former being Microsoft-owned and used in Visual Studio and Visual Studio Code, while the latter is a vendor-neutral, open-source alternative designed for VS Code-compatible editors like Eclipse Theia, Gitpod, SAP Business Application Studio, and others.

At first, the researchers found at least 24 malicious extensions, and as soon as those were removed – new ones popped up. The extensions, when installed on a Windows device, would deploy Lumma Stealer.

Two dozen new packages

Now, security researchers are saying that the campaign, which they’ve dubbed Glassworm, re-emerged with 24 new packages added across the two platforms.

To smuggle the malware, the attackers are using invisible Unicode characters which form an infostealer attempting to grab GitHub, npm, and OpenVSX accounts. From there, it tries to pull tokens and other valuables from 49 browser extension wallets.

Also, it deploys an HVNC client for remote access, and a SOCKS proxy for malicious traffic routing. According to BleepingComputer, the new attack was spotted by security analysts from Secure Annex, who claim the campaign targets a wide range of tools and developer frameworks like Flutter, Vim, Yaml, Tailwind, Svelte, React Native, and Vue.

The full list of packages can be found on this link.

In its writeup, BleepingComputer said it tipped off Microsoft about the attacks, and was told that the company is looking for ways to harden the defenses on the popular repository: “We continue to assess and improve our scanning and detections to prevent abuse. Microsoft encourages users to flag suspicious content through a “Report Abuse” link found on every extension page,” Redmond told the publication.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Under Musk, the Grok disaster was inevitable

This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on dystopian developments in AI, follow...

Why Coinbase derailed the crypto industry’s political future

Brian Armstrong, chief executive officer of Coinbase Global Inc., speaks to members of the media on Capitol Hill in Washington, DC, US, on Thursday,...

Kaoss Pad V is the first major upgrade to Korg’s touch-based effects in 13 years

The Kaoss Pad has seen many different iterations, but the mainline effect unit and sampler hasn't received an update since the launch of the...

Here are the 10 deals worth grabbing from Best Buy’s winter sales event

Sony’s terrific Bravia 8 II is $900 off for a limited time. Good deals are often hard to come by at the beginning of the...

‘Sharp, irreversible hikes’: Think RAM price surges are bad? Analysts say AI will cause SSDs’ NAND components to shoot up in price permanently –...

NAND flash pricing is shifting away from short-term cycles toward structural pressureTrendForce data shows inventory movements no longer dictate SSD component costsSuppliers are limiting...

Forget Landman season 3 — I pitched Ali Larter the Taylor Sheridan spinoff I’m desperate to see on Paramount+, and she’s 100% ‘game’

I'm quite literally distraught that this weekend marks the end of Landman season 2. While Cami (Demi Moore) has come through with more vigor...

Lavazza’s A Modo Mio Deséa makes delicious espresso and a decent cappuccino – if you use the right milk

Lavazza A Mio Modo Deséa: one-minute reviewThe Lavazza A Modo Mio Deséa is a compact capsule coffee maker with optional milk-frothing for cappuccinos and...

The Eureka Ergonomic GTG Wave gaming desk looks fancy, and feels great for PC gaming — but you’ll probably want a desk mat

Eureka Ergonomic GTG Wave: Two-minute reviewIf you're looking for one of the best gaming desks, you're probably already aware that these fancy tables often...

iPhone 18 Pro video leak gives us a look at the phone’s potential design and colors – here’s what’s changing

A video leak shows off the iPhone 18 ProColor and Dynamic Island changes are expectedIt should launch in September 2026In our iPhone 17 Pro...

This is the year of wireless speakers as design pieces — here are 6 I loved from CES 2026 and can’t wait to hear...

As pop legend Sir Cliff Richard once sung while rollerskating around wearing a Sony Walkman: I like small speakers. I like tall speakers. If...