Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

Benchmark raises $225 million in special funding to double Cerebras

AI startup founder says he plans a ‘March for Billionaires’ to protest California’s wealth tax

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » GlassWorm returns with 24 malicious extensions masquerading as popular developer tools
Identity

GlassWorm returns with 24 malicious extensions masquerading as popular developer tools

userBy userDecember 2, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 2, 2025Ravi LakshmananMalware/Blockchain

The supply chain campaign known as GlassWorm has gained momentum again, with 24 extensions masquerading as popular developer tools and frameworks, including Flutter, React, Tailwind, Vim, and Vue, infiltrating both Microsoft Visual Studio Marketplace and Open VSX.

GlassWorm was first documented in October 2025, detailing its use of the Solana blockchain for command and control (C2) and collection of npm, Open VSX, GitHub, and Git credentials, exfiltrating cryptocurrency assets from dozens of wallets, and turning developer machines into attacker-controlled nodes for other criminal activities.

The most important aspect of this campaign is the misuse of stolen credentials to compromise additional packages and extensions, thereby spreading the malware like a worm. Despite continued efforts by Microsoft and Open VSX, the malware resurfaced for a second time last month, with attackers observed targeting GitHub repositories.

The latest wave of GlassWorm campaigns, discovered by Secure Annex’s John Tuckner, include a total of 24 extensions across both repositories. The list of identified extensions is below –

cyber security

VS Code Marketplace:

iconkieftwo.icon-theme-materiall prisma-inc.prisma-studio-assistance (removed after December 1, 2025) prettier-vsc.vsce-prettier flutcode.flutter-extension csvmech.csvrainbow codevsce.codelddb-vscode saoudrizvsce.claude-devsce Clangdcode.clangd-vsce cweijamysq.sync-settings-vscode bphpburnsus.iconesvscode klustfix.kluster-code-verify vims-vsce.vscode-vim yamlcode.yaml-vscode-extension solblanco.svetle-vsce vsceue.volar-vscode redmat.vscode-quarkus-pro msjsdreact.react-native-vsce

Open VSX.

bphpburn.icons-vscode tailwind-nuxt.tailwindcss-for-react flutcode.flutter-extension yamlcode.yaml-vscode-extension saoudrizvsce.claude-dev saoudrizvsce.claude-devsce Vitaik.solidity

Attackers have been found to artificially inflate download numbers to make extensions appear more trustworthy, make them appear more prominently in search results, often appearing very close to the actual project they’re spoofing, and trick developers into installing the extension.

“It appears that once an extension is initially approved, attackers can easily update the code with a new malicious version and easily bypass the filters,” Tuckner said. “Many code extensions start in an ‘activation’ context, and malicious code is slipped in shortly after activation occurs. ”

cyber security

The new iteration still relies on invisible Unicode tricks, but features Rust-based implants packaged within extensions. Nextron Systems said in its analysis of the “icon-theme-materiall” extension that it comes with two Rust implants that can target Windows and macOS systems.

A Windows DLL named os.node A macOS dynamic library named darwin.node

As observed in previous GlassWorm infections, the implant is designed to obtain C2 server details from the Solana blockchain wallet address and use them to download the next stage payload, an encrypted JavaScript file. As a backup, you can parse Google Calendar events to obtain C2 addresses.

“It’s rare for an attacker to publish more than 20 malicious extensions in a week across both of the most popular markets,” Tuckner said in a statement. “Many developers can be easily fooled by these extensions and put themselves at risk with just one click.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article‘I don’t know of any similar cases’: 4,000-year-old burial in little-known African kingdom baffles archaeologists
Next Article Researchers Live Camera Live Camera of Lazarus APT’s Remote Worker Plan
user
  • Website

Related Posts

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

February 7, 2026

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

February 6, 2026

China-linked DKnife AitM framework, routers targeted for traffic hijacking and malware distribution

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

Benchmark raises $225 million in special funding to double Cerebras

AI startup founder says he plans a ‘March for Billionaires’ to protest California’s wealth tax

From Svedka to Anthropic, brands are boldly leveraging AI in their Super Bowl ads

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.