BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GlassWorm Malware Hits 24 VS Code Extensions on Major Marketplaces

GlassWorm Malware Returns, Infecting 24 Developer Extensions Across Microsoft Visual Studio Marketplace and Open VSX Using Rust-Based Implants and Solana Blockchain for Command and Control

  • The GlassWorm supply chain Malware campaign resurfaced in December 2025, targeting extensions in Microsoft Visual Studio Marketplace and Open VSX.
  • The campaign involves 24 malicious extensions impersonating popular developer tools like Flutter, React, and Tailwind.
  • Attackers use stolen credentials to spread malware by compromising legitimate packages and inflating download counts to appear trustworthy.
  • Malicious extensions include Rust-based implants that fetch command-and-control data from the Solana Blockchain and Google Calendar events.
  • This campaign converts developer machines into nodes for wider malicious activities and drains cryptocurrency wallets.

In December 2025, the GlassWorm supply chain malware campaign emerged again, affecting both the Microsoft Visual Studio Marketplace and Open VSX platforms. This episode involved 24 extensions posing as widely-used developer tools and frameworks, including Flutter, React, Tailwind, Vim, and Vue.

- Advertisement -

Originally detected in October 2025, GlassWorm uses the Solana blockchain for its command-and-control (C2) operations. The malware harvests credentials from npm, Open VSX, GitHub, and Git to steal cryptocurrency assets and convert infected developer machines into attacker-controlled nodes. The stolen credentials also facilitate compromising additional packages, allowing the malware to spread like a worm. Efforts to remove the threat by Microsoft and Open VSX have been challenged by the malware’s persistence, with attacks recently targeting GitHub repositories as well.

Cybersecurity expert John Tuckner of Secure Annex identified 24 malicious extensions in the latest wave, divided between the two marketplaces. Notable compromised extensions include iconkieftwo.icon-theme-materiall, flutcode.flutter-extension, and msjsdreact.react-native-vsce on VS Code Marketplace, alongside tailwind-nuxt.tailwindcss-for-react and vitalik.solidity on Open VSX. One of the extensions, prisma-inc.prisma-studio-assistance, was removed by Microsoft on December 1, 2025.

Attackers artificially inflate download counts to make these extensions appear legitimate and increase their visibility near authentic projects. According to Tuckner, “Once the extension has been approved initially, the attacker seems to easily be able to update code with a new malicious version and easily evade filters.” The malicious code activates soon after the legitimate extension launches.

This iteration of GlassWorm includes Rust-based implants embedded in the extensions. An analysis of the “icon-theme-materiall” extension by Nextron Systems showed two implants targeting Windows and macOS: a Windows DLL named os.node and a macOS dynamic library darwin.node. These implants retrieve C2 server details from the Solana blockchain wallet address or parse Google Calendar events as a fallback, then download encrypted JavaScript payloads to execute further commands.

- Advertisement -

Tuckner emphasized the scale of this attack, noting “Rarely does an attacker publish 20+ malicious extensions across both of the most popular marketplaces in a week.” This poses significant risk as many developers could be compromised with just one click.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Anthropic’s Mythos Poses Crypto Hacking Peril

Anthropic is granting early access to its powerful "Mythos" AI model to major tech...

South Korea’s new crypto bill targets stablecoins, tokenization

South Korea's ruling party is drafting a bill that would regulate stablecoins as foreign...

Anthropic Uses Powerful AI Model to Find Security Flaws

Anthropic launches Project Glasswing, a cybersecurity initiative using its powerful new AI model, Claude...

Shiba Inu Rallies as US-Iran Ceasefire Boosts Crypto Market

The U.S.-Iran ceasefire has boosted risk appetite, fueling a cryptocurrency market surge.Shiba Inu (SHIB)...

Theta March 2026: TDROP 2.0, AI Agents, EdgeCloud Expand

Theta EdgeCloud now accepts its TDROP token for AI compute services, enhancing its utility.The...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading