Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack
    Cybersecurity

    Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack

    adminBy adminFebruary 3, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    N8n vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The GlassWorm malware has appeared on the Open VSX marketplace again, after a publisher’s account was compromised in a supply chain attack, Socket reports.

    On January 30, a threat actor published malicious versions of four established VS Code extensions with over 22,000 combined downloads.

    The extensions contained code that would execute at runtime, evade systems with Russian locales, resolve command-and-control (C&C) data from Solana transaction memos, and run additional code.

    Consistent with previously observed activity, the extensions were repurposed to deploy a GlassWorm loader, but the fresh attack did not rely on typosquatting or cloned tools.

    “By contrast, these four extensions were published under an established publisher account with a multi-extension history and meaningful adoption signals across ecosystems,” Socket notes.

    The publisher also maintains Visual Studio Marketplace listings with thousands of downloads, but the analyzed incident only concerns Open VSX extensions.

    Advertisement. Scroll to continue reading.

    “The threat actor published poisoned updates through an established publisher identity, and the Open VSX security team assessed the incident as consistent with leaked tokens or other unauthorized publishing access,” Socket notes.

    macOS malware

    The threat actor hid a nearly identical loader in the extension.js file of each extension. It loads code that profiles the system and receives instructions from a transaction memo on Solana.

    The loader explicitly focuses on macOS systems, moving to the next stage only if OS checks are passed. The second payload is a Node.js JavaScript implant designed for data theft and persistence.

    Once executed, the malware targets Firefox- and Chrome-based browsers to steal cookies, form history, login files, and wallet-extension artifacts. It also searches the system for Safari cookies, desktop cryptocurrency wallets, and macOS keychain, Apple Notes, and FortiClient VPN data.

    Finally, it collects documents from the Desktop, Documents, and Downloads folders, and stages all the harvested information for exfiltration to hardcoded external destinations.

    According to Socket, the malware specifically targets developer credentials and configuration, such as AWS and SSH information, increasing the risk of account compromise and lateral movement activities.

    “This campaign shows a clear escalation in Open VSX supply chain abuse. The threat actor blends into normal developer workflows, hides execution behind encrypted, runtime-decrypted loaders, and uses Solana memos as a dynamic dead drop to rotate staging infrastructure without republishing extensions,” Socket notes.

    Related: Notepad++ Supply Chain Hack Conducted by China via Hosting Provider

    Related: eScan Antivirus Delivers Malware in Supply Chain Attack

    Related: ‘PackageGate’ Flaws Open JavaScript Ecosystem to Supply Chain Attacks

    Related: Shai-Hulud Supply Chain Attack Led to $8.5 Million Trust Wallet Heist

    Account Attack Fresh GlassWorm Hijacked open Publisher VSX
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleMy Favorite Beats Headphones Are More Than Half Off
    Next Article Firefox is giving users the AI tool they really want: A kill switch
    admin
    • Website

    Related Posts

    The Open Standard That Gives AI Systems A Structured View Of Your Business

    June 1, 2026

    One Step Forward, Two Steps Back: CA’s AB 1856 Exempts Open Source But Expands Age-Gating

    May 30, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google clarifies sensitive audience targeting rules for Demand Gen campaigns

    June 5, 2026

    LGBT Q&A Season 1 Recap: Staying Safer Online

    June 5, 2026

    AI Apps You Can Use Right Now to Grow Your Website

    June 5, 2026

    Google Analytics Is Adding Google Business Profile Data

    June 5, 2026
    Categories
    • Blogging (90)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (241)
    • SEO & Digital Marketing (1,387)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (335)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google clarifies sensitive audience targeting rules for Demand Gen campaigns

    June 5, 2026

    LGBT Q&A Season 1 Recap: Staying Safer Online

    June 5, 2026

    AI Apps You Can Use Right Now to Grow Your Website

    June 5, 2026
    Most Popular
    • Google clarifies sensitive audience targeting rules for Demand Gen campaigns
    • LGBT Q&A Season 1 Recap: Staying Safer Online
    • AI Apps You Can Use Right Now to Grow Your Website
    • Google Analytics Is Adding Google Business Profile Data
    • What to do now that AI Overviews turned search into reading sessions
    • How Cisco IT cut observability costs by 86% and eliminated major network outages
    • A how-to guide (+ top tools)
    • What It Is and How It Works in 2026
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.