Eclipse Foundation revoked a small number of leaked access tokens for the Open VSX extension marketplace after a report from Wiz revealed that several Visual Studio Code extensions had inadvertently exposed their tokens in public repositories. This exposure could have allowed attackers to take control of extensions and distribute malware, posing a significant supply chain risk. The foundation confirmed that the leaks were due to developer mistakes, not a compromise of Open VSX infrastructure, and has since implemented new security measures, including a token prefix format and reduced token lifetimes. Additionally, extensions flagged as part of the "GlassWorm" campaign by Koi Security were removed, and the foundation clarified that the reported download numbers were likely inflated by bots and threat actor tactics.
The GlassWorm campaign involved the use of hidden malicious code injected with invisible Unicode Private Use Area (PUA) characters, a technique previously observed in npm packages and now seen in compromised Open VSX extensions. Security researchers noted that the same threat actor has shifted focus to GitHub repositories, using increasingly stealthy methods to inject malware into legitimate-looking commits. The campaign highlights the evolving tactics of supply chain attackers and the importance of proactive security measures in open-source ecosystems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers provided law enforcement with additional information related to cryptocurrency exchanges and messaging platforms allegedly involved in the GlassWorm operation. This marked an escalation from technical reporting to active information-sharing for possible enforcement action.
Technical analysis published on November 10, 2025 attributed the GlassWorm activity to a likely Russian-speaking threat actor. Researchers said the operation used the open-source RedExt browser-extension command-and-control framework and blockchain-based infrastructure to update C2 details.
By November 10, 2025, multiple reports said the renewed campaign had affected at least 60 organizations worldwide, including a major Middle Eastern government entity. Researchers also described the malware as using stolen GitHub, Git, and npm credentials to spread into repositories and maintain persistence.
On November 6, 2025, researchers found three additional malicious VS Code extensions on Open VSX, showing that the campaign had resurfaced despite earlier token revocations. These extensions added about 10,000 more downloads to the operation and reused the same invisible-Unicode obfuscation technique.
Aikido researchers reported a new wave of attacks on GitHub JavaScript repositories using hidden Unicode Private Use Area characters to conceal malicious code. The campaign, tied to the same actor behind the npm and Open VSX incidents, used stolen credentials and Solana-hosted payload delivery, raising concerns about worm-like propagation.
Following the discovery of leaked tokens, the Eclipse Foundation/Open VSX team removed malicious extensions and revoked or rotated compromised access tokens to contain the attack. The registry also began planning additional protections such as shorter token lifetimes, faster revocation, and automated extension scanning.
Wiz researchers identified more than 550 exposed secrets across the Microsoft VS Code and Open VSX extension ecosystems, including tokens that could be abused to publish malicious extensions. This discovery linked leaked developer credentials to the ongoing GlassWorm supply-chain activity.
By mid-October 2025, the broader GlassWorm supply-chain campaign had already compromised about a dozen VS Code/Open VSX extensions, generating roughly 35,000 downloads. The malware used invisible Unicode characters to hide JavaScript payloads that stole developer credentials and cryptocurrency-related data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourceaikido.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.