Threats & Adversaries · Supply Chain
Sleeper Extensions Turn Open VSX Into Malware Delivery Benign-looking extension clones can be a delayed compromise, not a clean install. The standard response of checking the first publish is not enough, because these packages are seeded under fresh accounts and only later updated to deliver malware through the normal update path.
Socket is tracking 73 impersonation extensions tied to GlassWorm on Open VSX. At least six have already been activated to deliver malware, and the wider campaign also compromised Bitwarden CLI 2026.4.0 through a GitHub Action in Bitwarden’s CI/CD pipeline.
The risk is persistence through trust. Once a sleeper extension is installed, later updates can turn it into a delivery vehicle at scale without an obvious initial warning.
5 sources · Apr 28
Timeline Sources Apr 28 CSO Online
More fake extensions linked to GlassWorm found in Open VSX code marketplace
73 new phony extensions added this month, say researchers at Socket, as the supply chain attacks continue.
original Apr 28 Dark Reading
Fresh Wave of GlassWorm VS Extensions Slices Through Supply Chain
Attackers continue to scale a campaign to seed Open VSX with seemingly benign VS Code extensions that spread self-propagating malware.
original Apr 28 SecurityWeek
Dozens of Open VSX Extension Clones Linked to GlassWorm Malware
Over 70 cloned Open VSX extensions are likely sleeper extensions designed to distribute malware.
original Part of the PlainSec briefing for 2026-04-29
Every edition of this story: Sleeper Extensions Turn Open VSX Into Malware Delivery
More from today
Threats & Adversaries · Supply Chain
Sleeper Extensions Turn Open VSX Into Malware Delivery Benign-looking extension clones can be a delayed compromise, not a clean install. The standard response of checking the first publish is not enough, because these packages are seeded under fresh accounts and only later updated to deliver malware through the normal update path.
Socket is tracking 73 impersonation extensions tied to GlassWorm on Open VSX. At least six have already been activated to deliver malware, and the wider campaign also compromised Bitwarden CLI 2026.4.0 through a GitHub Action in Bitwarden’s CI/CD pipeline.
The risk is persistence through trust. Once a sleeper extension is installed, later updates can turn it into a delivery vehicle at scale without an obvious initial warning.
5 sources · Apr 28
Timeline Sources Apr 28 CSO Online
More fake extensions linked to GlassWorm found in Open VSX code marketplace
73 new phony extensions added this month, say researchers at Socket, as the supply chain attacks continue.
original Apr 28 Dark Reading
Fresh Wave of GlassWorm VS Extensions Slices Through Supply Chain
Attackers continue to scale a campaign to seed Open VSX with seemingly benign VS Code extensions that spread self-propagating malware.
original Apr 28 SecurityWeek
Dozens of Open VSX Extension Clones Linked to GlassWorm Malware
Over 70 cloned Open VSX extensions are likely sleeper extensions designed to distribute malware.
original Part of the PlainSec briefing for 2026-04-29
Every edition of this story: Sleeper Extensions Turn Open VSX Into Malware Delivery
More from today