Minacce e avversari · Supply chain
GlassWorm ha pubblicato 72 estensioni maligne su Open VSX per colpire sviluppatori. Sono stati identificati 151 repository GitHub infetti. Gli operatori hanno abusato di extensionPack e extensionDependencies per indurre estensioni fidate a scaricare payload collegati a GlassWorm.
3 fonti · 17 mar
BleepingComputer
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions.
originaleDark Reading
GlassWorm Malware Evolves to Hide in Dependencies
Dozens of updated, malicious GlassWorm extensions have infested Open VSX, threatening software development supply chains.
originaleThe Hacker News
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers
GlassWorm campaign used 72 malicious Open VSX extensions and infected 151 GitHub repositories, enabling stealth supply-chain attacks on developers.
originalePart of the PlainSec briefing for 2026-03-15
Every edition of this story: GlassWorm Distribuisce 72 Estensioni Open VSX Maligne