Sleeper Extensions Turn Open VSX Into Malware Delivery

Benign-looking extension clones can be a delayed compromise, not a clean install. The standard response of checking the first publish is not enough, because these packages are seeded under fresh accounts and only later updated to deliver malware through the normal update path. Socket is tracking 73 impersonation extensions tied to GlassWorm on Open VSX. At least six have already been activated to deliver malware, and the wider campaign also compromised Bitwarden CLI 2026.4.0 through a GitHub Action in Bitwarden’s CI/CD pipeline. The risk is persistence through trust. Once a sleeper extension is installed, later updates can turn it into a delivery vehicle at scale without an obvious initial warning.

Part of the PlainSec briefing for 2026-04-29

Sources