Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack
    Cybersecurity

    Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack

    adminBy adminFebruary 3, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    N8n vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The GlassWorm malware has appeared on the Open VSX marketplace again, after a publisher’s account was compromised in a supply chain attack, Socket reports.

    On January 30, a threat actor published malicious versions of four established VS Code extensions with over 22,000 combined downloads.

    The extensions contained code that would execute at runtime, evade systems with Russian locales, resolve command-and-control (C&C) data from Solana transaction memos, and run additional code.

    Consistent with previously observed activity, the extensions were repurposed to deploy a GlassWorm loader, but the fresh attack did not rely on typosquatting or cloned tools.

    “By contrast, these four extensions were published under an established publisher account with a multi-extension history and meaningful adoption signals across ecosystems,” Socket notes.

    The publisher also maintains Visual Studio Marketplace listings with thousands of downloads, but the analyzed incident only concerns Open VSX extensions.

    Advertisement. Scroll to continue reading.

    “The threat actor published poisoned updates through an established publisher identity, and the Open VSX security team assessed the incident as consistent with leaked tokens or other unauthorized publishing access,” Socket notes.

    macOS malware

    The threat actor hid a nearly identical loader in the extension.js file of each extension. It loads code that profiles the system and receives instructions from a transaction memo on Solana.

    The loader explicitly focuses on macOS systems, moving to the next stage only if OS checks are passed. The second payload is a Node.js JavaScript implant designed for data theft and persistence.

    Once executed, the malware targets Firefox- and Chrome-based browsers to steal cookies, form history, login files, and wallet-extension artifacts. It also searches the system for Safari cookies, desktop cryptocurrency wallets, and macOS keychain, Apple Notes, and FortiClient VPN data.

    Finally, it collects documents from the Desktop, Documents, and Downloads folders, and stages all the harvested information for exfiltration to hardcoded external destinations.

    According to Socket, the malware specifically targets developer credentials and configuration, such as AWS and SSH information, increasing the risk of account compromise and lateral movement activities.

    “This campaign shows a clear escalation in Open VSX supply chain abuse. The threat actor blends into normal developer workflows, hides execution behind encrypted, runtime-decrypted loaders, and uses Solana memos as a dynamic dead drop to rotate staging infrastructure without republishing extensions,” Socket notes.

    Related: Notepad++ Supply Chain Hack Conducted by China via Hosting Provider

    Related: eScan Antivirus Delivers Malware in Supply Chain Attack

    Related: ‘PackageGate’ Flaws Open JavaScript Ecosystem to Supply Chain Attacks

    Related: Shai-Hulud Supply Chain Attack Led to $8.5 Million Trust Wallet Heist

    Account Attack Fresh GlassWorm Hijacked open Publisher VSX
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleMy Favorite Beats Headphones Are More Than Half Off
    Next Article Firefox is giving users the AI tool they really want: A kill switch
    admin
    • Website

    Related Posts

    Hackers Abuse QEMU for Defense Evasion

    April 21, 2026

    Vercel Employee’s AI Tool Access Led to Data Breach

    April 21, 2026

    SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files

    April 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    WhatsApp’s paid subscription starts rolling out to some

    April 21, 2026

    Hackers Abuse QEMU for Defense Evasion

    April 21, 2026

    Winning Google Ads Campaign Structures For DTC Ecommerce

    April 21, 2026

    You’ll have one last chance to save on these top-tier Google TV projectors before launch

    April 21, 2026
    Categories
    • Blogging (66)
    • Cybersecurity (1,417)
    • Privacy & Online Earning (174)
    • SEO & Digital Marketing (860)
    • Tech Tools & Mobile / Apps (1,706)
    • WiFi / Internet & Networking (234)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    WhatsApp’s paid subscription starts rolling out to some

    April 21, 2026

    Hackers Abuse QEMU for Defense Evasion

    April 21, 2026

    Winning Google Ads Campaign Structures For DTC Ecommerce

    April 21, 2026
    Most Popular
    • WhatsApp’s paid subscription starts rolling out to some
    • Hackers Abuse QEMU for Defense Evasion
    • Winning Google Ads Campaign Structures For DTC Ecommerce
    • You’ll have one last chance to save on these top-tier Google TV projectors before launch
    • Vercel Employee’s AI Tool Access Led to Data Breach
    • The Internet Still Works: Reddit Empowers Community Moderation
    • This Bright and Powerful Blink Floodlight Camera Is Over Half Off Right Now
    • SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.