BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GlassWorm Malware Hits Open VSX via Developer Hack

Malicious extension updates hijack developer account, deliver GlassWorm malware to steal crypto and credentials

  • Threat actors compromised a legitimate developer’s account on the Open VSX Registry to publish malicious versions of four extensions.
  • The poisoned extensions delivered the GlassWorm malware loader, designed to steal cryptocurrency data and developer credentials.
  • The malware specifically avoided infecting machines with a Russian locale, a common evasion tactic.
  • Over 22,000 downloads had been recorded for the now-compromised extensions prior to the attack.

On February 2, 2026, cybersecurity researchers revealed a significant supply chain attack that compromised the popular Open VSX Registry. Unidentified threat actors hijacked a legitimate developer’s account to push malicious updates to widely used developer tool extensions. According to a report by Socket security researcher Kirill Boychenko, these poisoned versions delivered a dangerous malware loader.

- Advertisement -

The attack specifically targeted four extensions published under the account “oorzc,” including FTP/SFTP/SSH Sync Tool and vscode mindmap. These extensions had accumulated more than 22,000 downloads before the malicious releases were published. The Open VSX security team assessed that the developer’s publishing credentials were compromised, possibly through a leaked token.

Consequently, the malicious updates delivered a payload associated with the known GlassWorm campaign. This malware used an EtherHiding technique to fetch command-and-control servers. It was also programmed to profile a victim’s machine and avoid execution if a Russian locale was detected.

Meanwhile, the malware’s primary function was to steal sensitive information for financial gain. Its targets included data from Firefox and Chromium-based browsers, such as login credentials and cryptocurrency wallet extensions like MetaMask. It also hunted for specific cryptocurrency wallet files from Electrum, Exodus, Ledger Live, and Trezor Suite.

The malware further sought developer credentials from directories like `~/.aws` and `~/.ssh`. Boychenko noted, “The payload includes routines to locate and extract authentication material used in common workflows.” This data theft posed severe risks for lateral movement within enterprise environments.

- Advertisement -

However, this incident marked a tactical shift in the GlassWorm campaign’s methods. Instead of using typosquatting, the actors leveraged a legitimate, compromised developer account. Socket said this approach allowed the threat actor to blend into normal workflows and hide behind encrypted loaders.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tether Sets Two-Week Deadline for $500B Fundraise

Tether is reportedly giving investors a two-week deadline to commit to a $500 billion...

Ethereum Foundation Nears 70K ETH Staking Goal After Latest $92M Batch

The Ethereum Foundation staked over 45,000 ETH, worth more than $92 million, on Friday.This...

Dmail Network Shuts Down After Five-Year Decentralized Run

Decentralized email platform Dmail Network will officially begin ceasing its services on May 15...

Bank of Canada Study: Aave V3 Had Zero Bad Loans in 2024

A Bank of Canada staff analysis found Aave V3 had zero non-performing loans in...

Tech Giants Found AI Payment Protocol Group

The x402 Foundation launched on Thursday by the Linux Foundation to govern an AI...

Must Read

6 Best VPN Providers That Accept Monero

Privacy and anonymity are probably the most important things that we should all consider in today's internet era. Although there are a lot of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading