GlassWorm Malware Strikes Again: 73 OpenVSX Extensions Compromised

Date:

Title: New GlassWorm Malware Targets OpenVSX with Sleeper Extensions

A recent surge in cyberattacks has been reported, focusing on the OpenVSX ecosystem. Dubbed the GlassWorm campaign, this new wave has introduced 73 “sleeper” extensions that appear harmless upon installation but activate to deliver malware after an update.

Currently, six of these extensions have been confirmed to deliver malicious payloads, while the status of the remaining extensions remains uncertain. Developers using these extensions are at risk, as the attacker’s strategy has shifted to embedding malware in future updates rather than directly in the initial installation.

The impact of this attack could be severe, potentially compromising sensitive information such as cryptocurrency wallet data and developer credentials. To protect against this threat, developers are advised to avoid installing unfamiliar extensions, monitor updates closely, and rotate all credentials if they suspect exposure.

Risk Level: High

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...