Home / Companies / Socket / Blog / Post Details
Content Deep Dive

73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
980
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

The GlassWorm campaign, targeting Open VSX, has escalated with Socket tracking a new cluster of 73 impersonation extensions connected to previous sleeper-extension activities. These extensions, initially harmless, are published by newly created GitHub accounts and are later weaponized to deliver malware. This tactic, known as sleeper extensions, builds trust before activating malware through updates. The campaign mirrors past GlassWorm strategies of publishing cloned or impersonating extensions without an obvious payload and later updating them to deliver malware. The current wave involves cloned listings that resemble legitimate extensions, employing social engineering to gain installs before introducing malware. Notably, the campaign has shifted from embedding loaders directly in extensions to using extensionPack and extensionDependencies for transitive delivery, with some variants utilizing external payload retrieval or bundled native binaries. This diversification of delivery mechanisms complicates detection, as the source code alone no longer reveals malicious behavior. Socket has marked these extensions for user protection and continues to track the campaign's evolution on their dedicated GlassWorm v2 page.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Vector Search 1 1,739 413 146 -27%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.