Home / Companies / Socket / Blog / Post Details
Content Deep Dive

72 Malicious Open VSX Extensions Linked to GlassWorm Campaign Now Using Transitive Dependencies

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,820
Company Posts That Month
34
Language
English
Hacker News Points
-
Post removed?
No
Summary

GlassWorm has evolved its method of spreading malware by exploiting extensionPack and extensionDependencies in Open VSX, allowing initially benign extensions to become delivery vehicles for malicious extensions in later updates. This technique lowers the visibility of the malicious components and requires continuous auditing of extension histories as a one-time review is insufficient for risk assessment. The campaign retains its core techniques like staged JavaScript execution, Russian locale/timezone geofencing, and Solana transaction memos, while implementing new obfuscation strategies and rotating infrastructure to evade detection. The primary attack surface is the Open VSX/VS Code extension installation path, targeting developer workstations and related sensitive data. Despite efforts to remove malicious extensions, ongoing updates and incomplete takedowns highlight the need for vigilant monitoring of extension relationships and changes.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 1,162 174 80 -4%
MCP 1 2,803 327 131 -43%
Vector Search 1 1,668 286 111 +15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.