Home / Companies / Socket / Blog / Post Details
Content Deep Dive

GlassWorm Sleeper Extensions Activate on Open VSX, Shift to GitHub-Hosted VSIX Malware

Blog post from Socket

Post Details
Company
Date Published
Author
Philipp Burckhardt and Peter van der Zee
Word Count
3,676
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent wave of GlassWorm malware, identified by Socket, has infiltrated OpenVSX extensions, demonstrating a sophisticated evasion technique by utilizing GitHub for payload delivery. Initially innocent-looking extensions, often typosquats, are published without malware but later updated to introduce malicious loaders. Between March 17 and 18, 2026, several dormant extensions were activated, transforming into extension packs that drew in malicious dependencies from GitHub, bypassing OpenVSX-hosted dependencies. The Eclipse Foundation's OpenVSX security team responded by removing many malicious extensions and associated publisher accounts, although some remained live. Socket's AI Scanner flagged these extensions, including lauracode.wrap-selected-code, which directly installed malware across multiple IDEs. The campaign's resilience is underscored by its use of blockchain for command and control, multi-stage payloads, and GitHub as delivery infrastructure, complicating takedown efforts and enhancing persistence.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 6,457 1,307 242 +28%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.