GlassWorm returns through 73 sleeper OpenVSX extensions

Researchers at Socket say a new GlassWorm wave is targeting the OpenVSX extension ecosystem through 73 “sleeper” extensions that become malicious after an update. Six of the extensions have already been activated and are delivering malware, while the rest are under suspicion or appear dormant.

GlassWorm returns through 73 sleeper OpenVSX extensions

Researchers are warning about a new wave of the GlassWorm supply chain campaign, this time centered on 73 OpenVSX extensions that appear harmless at first and later turn malicious after an update. According to application security company Socket, six of the extensions have already been activated and are delivering malware, while the remaining listings are considered dormant or suspicious.

The key difference in this wave is timing. When the extensions are first uploaded, they look benign, but they are designed to fetch or activate malicious code later, which hides the attacker’s real intent from developers who only review the initial listing.

⚡ New to this?

This matters because extension marketplaces are trusted software distribution channels, and attackers are abusing that trust to slip malware into developer tools. A supply chain attack is when bad code enters through software a team already relies on, instead of through a direct break-in. OpenVSX is an extension registry used by code editors, so a malicious extension can expose developer credentials, keys, and other secrets.

🦞 OpenClaw angle

If your automation stack installs editor or build extensions from OpenVSX, treat them as part of your attack surface and pin them by publisher and unique ID, not just name and icon. Add an update review step for any extension that can execute code, fetch remote payloads, or ship .node binaries, because those are the kinds of loaders Socket described. If any affected extension was installed in a self-hosted workflow, rotate secrets, API tokens, SSH keys, and wallet credentials, then rebuild affected environments from a clean baseline rather than trying to patch around the compromise.

Socket said the current count may change as new updates appear, but the pattern matches earlier GlassWorm activity. The campaign has been active since October and was first identified using invisible Unicode characters to conceal malicious code that stole cryptocurrency wallet data and developer credentials.

Since then, GlassWorm has spread across multiple ecosystems, including GitHub repositories, npm packages, the Visual Studio Code Marketplace and OpenVSX. Researchers have also observed related activity aimed at macOS users through trojanized crypto wallet clients.

A separate wave in mid-March 2026 affected hundreds of repositories and dozens of extensions. That larger operation was noisy, according to researchers, and left enough traces that multiple teams spotted it early and helped block it.

Socket said the latest activity suggests the attacker may be changing tactics. Instead of embedding the payload directly inside the extension from the start, the attacker is now submitting harmless-looking extensions to a single ecosystem and adding the malicious payload in a later update.

The 73 extensions identified in the latest campaign are clones of legitimate listings, according to Socket. In one case, the attacker copied the icon of the real extension and used a similar name and description, with the publisher name and unique identifier being the main clues that something was wrong.

Rather than containing the malware outright, the extensions act as thin loaders. Socket said some versions fetch a secondary VSIX package from GitHub at runtime and install it using command-line tools.

Other variants load compiled platform-specific modules, or .node files, that include the main logic for fetching more payloads and carrying out installation routines across supported editors. Some rely on heavily obfuscated JavaScript that decodes at runtime and then retrieves malicious extensions, sometimes using encrypted or fallback URLs.

Socket did not publish technical details about the newest payload. In earlier GlassWorm activity, the malware was used to steal cryptocurrency wallet data, credentials, access tokens, SSH keys and developer environment data.

The company said it has published the full list of the 73 extensions it believes are tied to the latest wave. Developers who installed any of them are being told to rotate all secrets and clean their environment.

Source: BleepingComputer ↗

More from Security News