GlassWorm expanded its software supply-chain campaign in the Open VSX ecosystem by publishing dozens of seemingly benign extensions that later pull in malicious components through the extensionPack and extensionDependencies manifest fields. Socket reported 73 malicious Open VSX extensions linked to the operation, while another report cited 72 newly identified packages, reflecting the same campaign and detection set. The technique allows attackers to establish trust with an initial standalone-looking extension and then, in a later update, silently install a hidden GlassWorm loader as a transitive dependency, defeating one-time review of the original package. The malicious listings impersonate common developer tools including formatters, linters, language support packages, and AI coding assistants to maximize installation volume.
The campaign preserves earlier GlassWorm tradecraft while improving evasion and resilience. Reported behaviors include staged JavaScript execution, Russian locale/timezone geofencing, use of Solana transaction memos as dead drops, and in-memory execution of follow-on code. Socket also observed infrastructure and loader changes, including reuse of 45[.]32[.]150[.]251, addition of 45[.]32[.]151[.]157 and 70[.]34[.]242[.]255, migration to a new Solana wallet, and a shift from a static AES-wrapped loader to heavier RC4/base64/string-array obfuscation with decryption material moved into HTTP response headers such as ivbase64 and secretkey. This is a substantive threat-intelligence and vulnerability-exposure story, not fluff, because it documents an active malicious campaign, specific delivery mechanisms, and concrete infrastructure tied to developer-targeted compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
After Socket reported the newly weaponized extensions, the Eclipse Foundation removed some malicious extensions and associated publisher accounts. However, several extensions published on March 18 remained live at the time of publication, showing remediation was still ongoing.
On March 17–18, 2026, previously benign-looking Open VSX extensions were converted into extension packs or direct droppers that installed malicious VSIX payloads from GitHub. This marked a shift from relying only on Open VSX-hosted dependencies to using GitHub-hosted payload delivery and enabled arbitrary code execution across multiple editors.
Subsequent reporting said Socket later connected more than 20 additional Open VSX extensions to the same GlassWorm activity beyond the initial 72. The added findings showed the campaign had expanded further across the ecosystem.
By March 13, 2026, Open VSX had removed most of the malicious transitive extensions identified by researchers, though some packages remained available. This indicated remediation was underway but incomplete.
On March 13, 2026, Socket reported that GlassWorm had evolved its Open VSX campaign by abusing extension manifest dependency fields to hide malware in later updates. The report described staged JavaScript execution, Russian geofencing, Solana memo dead drops, in-memory execution, stronger obfuscation, and rotating infrastructure.
Aikido linked the broader operation to intrusions affecting 151 GitHub repositories and two npm packages, where invisible Unicode-based payloads were inserted while commits were disguised as routine maintenance. The activity was reported as occurring from March 3 through March 9, 2026.
Since January 31, researchers identified at least 72 malicious Open VSX extensions linked to GlassWorm. The campaign abused the extensionPack and extensionDependencies manifest fields so trusted-looking extensions could later pull in malicious components transitively.
Researchers said the Open VSX portion of the GlassWorm campaign had been active since late January 2026, using spoofed extensions that initially appeared benign. Attackers later weaponized updates to turn them into malware delivery vehicles targeting developer environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
socket.dev
Open sourcescworld.com
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourceinfoworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesocket.dev
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.