GlassWorm was reported as a self-propagating supply-chain malware campaign that spread through developer ecosystems including the VS Code Marketplace, OpenVSX, npm, PyPI, and GitHub repositories. Reporting indicates the malware abused invisible Unicode characters to hide malicious logic inside extensions and packages, allowing payloads to evade casual review while embedding decoder routines, command-and-control markers, and other indicators of compromise. One wave specifically targeted macOS users through poisoned OpenVSX extensions, expanding the campaign beyond code repositories into developer workstations.
Security researchers and defenders responded by publishing detection guidance and tooling to hunt for GlassWorm artifacts across local Git repositories, VS Code extensions, and package dependencies. The open-source glassworm-hunter project was released to scan for hidden Unicode payloads, decoder patterns, C2 markers, and known malicious IOCs, reflecting concern that the campaign crossed multiple software distribution channels rather than a single marketplace. The incident highlights a broad software supply-chain intrusion in which trusted developer platforms were used to distribute stealthy malware concealed inside seemingly legitimate code.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
CrowdStrike and Sonatype linked the GlassWorm campaign to activity involving PyPI repositories and hijacked React Native npm packages with more than 30,000 weekly downloads. The reporting also described Solana blockchain-based command-and-control and additional credential- and wallet-theft capabilities, expanding the known scope and tradecraft of the campaign.
One day after the GlassWorm takedown, the OSV database withdrew 157 malware reports after maintainers concluded the submissions were likely automated false positives. The development was reported in the context of growing noise around supply-chain security reporting.
Following reporting on the coordinated disruption of GlassWorm, CrowdStrike said the operation was likely conducted by Russian threat actors. The attribution was based on CIS-avoidance logic, Russian-language comments in the malware, and broader tradecraft patterns.
CrowdStrike, working with Google and the Shadowserver Foundation, announced a coordinated disruption of all four command-and-control channels used by the GlassWorm campaign. The report said the operation targeted resilient infrastructure including Solana blockchain, BitTorrent DHT, Google Calendar, and VPS-hosted channels supporting the developer-focused supply-chain malware.
A public GitHub tool, glassworm-hunter, was released to detect GlassWorm indicators in VS Code extensions, npm and PyPI packages, and local Git repositories. The tool searches for invisible Unicode payloads, decoder patterns, command-and-control markers, and known malicious IOCs.
Technical analysis expanded the known scope of the GlassWorm campaign, describing activity across GitHub repositories, npm packages, Open VSX, and VS Code. The report characterized the operation as a multi-platform supply-chain intrusion using related tactics across ecosystems.
Reporting highlighted that GlassWorm was being used to target macOS users through malicious OpenVSX extensions. The coverage framed the activity as an active malware threat delivered through the extension marketplace.
GlassWorm was identified as a self-propagating supply-chain worm affecting the Open VSX and VS Code extension ecosystems. Early reporting described invisible-code techniques and malicious extension propagation as the core of the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
infoworld.com
Open sourcexakep.ru
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceendorlabs.com
Open sourceopensourcemalware.com
Open sourcetechradar.com
Open sourcekoi.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.