Security Affairs
Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

GlassWorm malware has resurfaced on the Open VSX registry

GlassWorm malware resurfaces in Open VSX and GitHub, infecting VS Code extensions weeks after its removal from the official marketplace. GlassWorm malware has resurfaced on the Open VSX registry and newly appeared in GitHub repositories, infecting three more VS Code extensions just weeks after its removal from the official marketplace, Koi Security researchers warn. In […]

GlassWorm malware

GlassWorm malware resurfaces in Open VSX and GitHub, infecting VS Code extensions weeks after its removal from the official marketplace.

GlassWorm malware has resurfaced on the Open VSX registry and newly appeared in GitHub repositories, infecting three more VS Code extensions just weeks after its removal from the official marketplace, Koi Security researchers warn.

In mid-October, hackers spread malware through about a dozen infected extensions to steal NPM, GitHub, and Git credentials. The malware also targets 49 cryptocurrency extensions. Koi Security reported around 35,000 downloads and warned that the malware could spread further by infecting other extensions and packages on compromised systems.

Koi researchers now report that three more VS Code extensions were infected on November 6, totaling approximately 10,000 downloads:

  • ai-driven-dev.ai-driven-dev (3,300 downloads)
  • adhamu.history-in-sublime-merge (4,000 downloads)
  • yasuyuky.transient-emacs (2,400 downloads)

Threat actors used a Solana blockchain transaction to update C2 addresses, while the exfiltration server stayed the same.

“we detected a new wave of GlassWorm infections. Three more extensions compromised. A fresh Solana blockchain transaction providing new C2 endpoints. Same attacker infrastructure, still fully operational.” reads Koi’s report.

The researchers breached the attacker’s server, discovering victims worldwide, including a major Middle Eastern government entity. GlassWorm now threatens critical infrastructure, spreading through the developer ecosystem and jumping from OpenVSX to GitHub using AI-generated commits to hide its malicious payloads.

Koi reports attackers stole victims’ credentials, likely using their devices as proxy infrastructure. Keylogger data shows a Russian-speaking actor using RedExt C&C, multiple crypto exchanges, and messaging platforms.

All three OpenVSX extensions use invisible Unicode malware that runs as JavaScript while appearing blank in editors. Koi notified law enforcement, but the campaign likely affects many more than identified.

On October 31, 2025, Aikido Security found that GlassWorm spread to GitHub, hiding invisible Unicode malware in AI-generated commits that looked legitimate.

GlassWorm malware
The invisible payload in the new wave of GlassWorm

The payloads, delivered via the same Solana blockchain method, confirm it’s GlassWorm. Using stolen GitHub credentials, attackers pushed malicious commits to new repositories, proving the worm’s self-propagating nature.

“GlassWorm demonstrates why visibility and governance across the entire software supply chain is no longer optional. When malware can be literally invisible, when worms can self-propagate through stolen credentials, when attack infrastructure can’t be taken down – traditional security tools aren’t enough.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, OpenVSX)