GlassWorm Malware Strikes Again: 73 OpenVSX Extensions Compromised

Date:

Title: New GlassWorm Malware Targets OpenVSX with Sleeper Extensions

A recent surge in cyberattacks has been reported, focusing on the OpenVSX ecosystem. Dubbed the GlassWorm campaign, this new wave has introduced 73 “sleeper” extensions that appear harmless upon installation but activate to deliver malware after an update.

Currently, six of these extensions have been confirmed to deliver malicious payloads, while the status of the remaining extensions remains uncertain. Developers using these extensions are at risk, as the attacker’s strategy has shifted to embedding malware in future updates rather than directly in the initial installation.

The impact of this attack could be severe, potentially compromising sensitive information such as cryptocurrency wallet data and developer credentials. To protect against this threat, developers are advised to avoid installing unfamiliar extensions, monitor updates closely, and rotate all credentials if they suspect exposure.

Risk Level: High

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...