GlassWorm Malware Hits 24 VS Code Extensions on Major Marketplaces

GlassWorm Malware Returns, Infecting 24 Developer Extensions Across Microsoft Visual Studio Marketplace and Open VSX Using Rust-Based Implants and Solana Blockchain for Command and Control

- Advertisement -
  • The GlassWorm supply chain Malware campaign resurfaced in December 2025, targeting extensions in Microsoft Visual Studio Marketplace and Open VSX.
  • The campaign involves 24 malicious extensions impersonating popular developer tools like Flutter, React, and Tailwind.
  • Attackers use stolen credentials to spread malware by compromising legitimate packages and inflating download counts to appear trustworthy.
  • Malicious extensions include Rust-based implants that fetch command-and-control data from the Solana Blockchain and Google Calendar events.
  • This campaign converts developer machines into nodes for wider malicious activities and drains cryptocurrency wallets.

In December 2025, the GlassWorm supply chain malware campaign emerged again, affecting both the Microsoft Visual Studio Marketplace and Open VSX platforms. This episode involved 24 extensions posing as widely-used developer tools and frameworks, including Flutter, React, Tailwind, Vim, and Vue.

- Advertisement -

Originally detected in October 2025, GlassWorm uses the Solana blockchain for its command-and-control (C2) operations. The malware harvests credentials from npm, Open VSX, GitHub, and Git to steal cryptocurrency assets and convert infected developer machines into attacker-controlled nodes. The stolen credentials also facilitate compromising additional packages, allowing the malware to spread like a worm. Efforts to remove the threat by Microsoft and Open VSX have been challenged by the malware’s persistence, with attacks recently targeting GitHub repositories as well.

Cybersecurity expert John Tuckner of Secure Annex identified 24 malicious extensions in the latest wave, divided between the two marketplaces. Notable compromised extensions include iconkieftwo.icon-theme-materiall, flutcode.flutter-extension, and msjsdreact.react-native-vsce on VS Code Marketplace, alongside tailwind-nuxt.tailwindcss-for-react and vitalik.solidity on Open VSX. One of the extensions, prisma-inc.prisma-studio-assistance, was removed by Microsoft on December 1, 2025.

Attackers artificially inflate download counts to make these extensions appear legitimate and increase their visibility near authentic projects. According to Tuckner, “Once the extension has been approved initially, the attacker seems to easily be able to update code with a new malicious version and easily evade filters.” The malicious code activates soon after the legitimate extension launches.

This iteration of GlassWorm includes Rust-based implants embedded in the extensions. An analysis of the “icon-theme-materiall” extension by Nextron Systems showed two implants targeting Windows and macOS: a Windows DLL named os.node and a macOS dynamic library darwin.node. These implants retrieve C2 server details from the Solana blockchain wallet address or parse Google Calendar events as a fallback, then download encrypted JavaScript payloads to execute further commands.

- Advertisement -

Tuckner emphasized the scale of this attack, noting “Rarely does an attacker publish 20+ malicious extensions across both of the most popular marketplaces in a week.” This poses significant risk as many developers could be compromised with just one click.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

KBC to Offer Bitcoin and Ether Trading to Belgian Retail Feb

KBC will let retail customers buy and sell Bitcoin and Ether via its Bolero...

UAT-8837: China-linked uses Sitecore zero-day to target CNI.

Cisco Talos links a China-aligned actor, tracked as UAT-8837, to intrusions against North American...

Gold Could Soar to $8,000 by 2026 Amid Central-Bank Buying!!

Rashad Hajiyev projected Gold could reach $8,000 by the end of 2026.Hajiyev warned the...

Political Liquidity and Quasi-QE Redefine Bitcoin Cycle Now!

Political and fiscal moves now sway crypto prices more than Bitcoin’s traditional four‑year cycle.Expansionary...

Crypto Whale Predicts 2026 Bull Run; Russell 2000 Rallies!!!

Markets show slow movement and high volatility as analysts watch for an inflection.Crypto Whale...
- Advertisement -

Must Read

7 Best Crypto To Invest In This Year

Investing in cryptocurrencies has become a popular way for people to diversify their investment portfolio and make potential profits.However, with so many cryptocurrencies available...
Bitcoin (BTC) $ 95,623.00 1.35%
Ethereum (ETH) $ 3,309.62 1.59%
XRP (XRP) $ 2.07 1.89%
Bittensor (TAO) $ 276.96 2.48%
Polkadot (DOT) $ 2.14 2.39%
Cardano (ADA) $ 0.392163 2.92%
Chainlink (LINK) $ 13.78 1.36%
Hyperliquid (HYPE) $ 24.94 0.68%
Monero (XMR) $ 704.17 0.86%
Hedera (HBAR) $ 0.117432 3.76%
Toncoin (TON) $ 1.72 3.77%