Minacce · 198 giorni fa
GlassWorm ha pubblicato 72 estensioni maligne su Open VSX per colpire sviluppatori. Sono stati identificati 151 repository GitHub infetti. Gli operatori hanno abusato di extensionPack e extensionDependencies per indurre estensioni fidate a scaricare payload collegati a GlassWorm.
3 fonti che coprono questa storia
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions.
GlassWorm Malware Evolves to Hide in Dependencies
Dozens of updated, malicious GlassWorm extensions have infested Open VSX, threatening software development supply chains.
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers
GlassWorm campaign used 72 malicious Open VSX extensions and infected 151 GitHub repositories, enabling stealth supply-chain attacks on developers.
Part of the PlainSec briefing for 2026-03-15