Home / Companies / Socket / Blog / Post Details
Content Deep Dive

GlassWorm Loader Hits Open VSX via Developer Account Compromise

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
2,317
Company Posts That Month
34
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket’s Threat Research team identified a developer-compromise supply chain attack via the Open VSX Registry, where malicious GlassWorm malware was embedded in four extensions originally published by a developer named oorzc. The compromised extensions, posing as legitimate tools, collectively garnered over 22,000 downloads, suggesting significant adoption before the malicious versions were released. This attack, which involved leaking publishing credentials or tokens, mirrors a pattern of recent GlassWorm-related activity that exploits blockchain technology for command and control, and targets macOS systems to steal sensitive data, including browser cookies, cryptocurrency wallet information, and developer credentials. The Open VSX security team responded by deactivating the compromised tokens, removing the malicious extensions, and flagging the developer's tools in their malware list, while previous waves of GlassWorm attacks had relied on typosquatting and brandjacking strategies. This incident underscores a growing threat in software supply chains, particularly through compromised developer accounts, which can lead to widespread credential theft and potential cloud account compromises.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 1,162 174 80 -4%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.