72 Malicious Open VSX Extensions Linked to GlassWorm Campaign Now Using Transitive Dependencies
Blog post from Socket
GlassWorm has evolved its method of spreading malware by exploiting extensionPack and extensionDependencies in Open VSX, allowing initially benign extensions to become delivery vehicles for malicious extensions in later updates. This technique lowers the visibility of the malicious components and requires continuous auditing of extension histories as a one-time review is insufficient for risk assessment. The campaign retains its core techniques like staged JavaScript execution, Russian locale/timezone geofencing, and Solana transaction memos, while implementing new obfuscation strategies and rotating infrastructure to evade detection. The primary attack surface is the Open VSX/VS Code extension installation path, targeting developer workstations and related sensitive data. Despite efforts to remove malicious extensions, ongoing updates and incomplete takedowns highlight the need for vigilant monitoring of extension relationships and changes.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 1,162 | 174 | 80 | -4% |
| MCP | 1 | 2,803 | 327 | 131 | -43% |
| Vector Search | 1 | 1,668 | 286 | 111 | +15% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.