BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GlassWorm Malware Hits 24 VS Code Extensions on Major Marketplaces

GlassWorm Malware Returns, Infecting 24 Developer Extensions Across Microsoft Visual Studio Marketplace and Open VSX Using Rust-Based Implants and Solana Blockchain for Command and Control

  • The GlassWorm supply chain Malware campaign resurfaced in December 2025, targeting extensions in Microsoft Visual Studio Marketplace and Open VSX.
  • The campaign involves 24 malicious extensions impersonating popular developer tools like Flutter, React, and Tailwind.
  • Attackers use stolen credentials to spread malware by compromising legitimate packages and inflating download counts to appear trustworthy.
  • Malicious extensions include Rust-based implants that fetch command-and-control data from the Solana Blockchain and Google Calendar events.
  • This campaign converts developer machines into nodes for wider malicious activities and drains cryptocurrency wallets.

In December 2025, the GlassWorm supply chain malware campaign emerged again, affecting both the Microsoft Visual Studio Marketplace and Open VSX platforms. This episode involved 24 extensions posing as widely-used developer tools and frameworks, including Flutter, React, Tailwind, Vim, and Vue.

- Advertisement -

Originally detected in October 2025, GlassWorm uses the Solana blockchain for its command-and-control (C2) operations. The malware harvests credentials from npm, Open VSX, GitHub, and Git to steal cryptocurrency assets and convert infected developer machines into attacker-controlled nodes. The stolen credentials also facilitate compromising additional packages, allowing the malware to spread like a worm. Efforts to remove the threat by Microsoft and Open VSX have been challenged by the malware’s persistence, with attacks recently targeting GitHub repositories as well.

Cybersecurity expert John Tuckner of Secure Annex identified 24 malicious extensions in the latest wave, divided between the two marketplaces. Notable compromised extensions include iconkieftwo.icon-theme-materiall, flutcode.flutter-extension, and msjsdreact.react-native-vsce on VS Code Marketplace, alongside tailwind-nuxt.tailwindcss-for-react and vitalik.solidity on Open VSX. One of the extensions, prisma-inc.prisma-studio-assistance, was removed by Microsoft on December 1, 2025.

Attackers artificially inflate download counts to make these extensions appear legitimate and increase their visibility near authentic projects. According to Tuckner, “Once the extension has been approved initially, the attacker seems to easily be able to update code with a new malicious version and easily evade filters.” The malicious code activates soon after the legitimate extension launches.

This iteration of GlassWorm includes Rust-based implants embedded in the extensions. An analysis of the “icon-theme-materiall” extension by Nextron Systems showed two implants targeting Windows and macOS: a Windows DLL named os.node and a macOS dynamic library darwin.node. These implants retrieve C2 server details from the Solana blockchain wallet address or parse Google Calendar events as a fallback, then download encrypted JavaScript payloads to execute further commands.

- Advertisement -

Tuckner emphasized the scale of this attack, noting “Rarely does an attacker publish 20+ malicious extensions across both of the most popular marketplaces in a week.” This poses significant risk as many developers could be compromised with just one click.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Canada Proposes Ban on Bitcoin ATMs to Curb Fraud

The Canadian government has proposed banning all cryptocurrency ATMs, citing their use as a...

CISA adds ConnectWise, Microsoft flaws to exploit

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited software flaws...

Inside Valdora Finance: How Liquid Vaults Are Bringing Real-World Yield On-Chain

In April 2026, Valdora Finance launched its first stablecoin liquid vaults on ZIGchain. The...

Robinhood shares drop 9.4% as crypto revenue halves

Robinhood shares fell 9.4% after-hours on Tuesday as the platform's Q1 earnings missed analyst...

Bitcoin Dips to $76K As Regulatory, Tech Worries Mount

Bitcoin retreated below $76,000 following declines in the tech-heavy Nasdaq 100 Index.Stalled regulatory progress...

Must Read

What Is the Dencun Upgrade for Ethereum?

The Dencun Upgrade for Ethereum is poised to revolutionize the blockchain landscape, offering improved scalability, efficiency, and groundbreaking features. Set to launch at the...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading