Representational image of a cybercriminal

Glassworm returns once again with a third round of VS code attacks | Daily Reports Online

Share


  • Glassworm campaign re-emerges with 24 malicious extensions on OpenVSX and Visual Studio marketplaces
  • Malware steals GitHub, npm, wallet tokens, and deploys HVNC client with SOCKS proxy
  • Targets frameworks like Flutter, React Native, Vue; Microsoft working to harden defenses

Malware is back on the OpenVSX and Microsoft Visual Studio marketplaces, researchers are warning. In mid-September this year, it was reported that cybercriminals were targeting crypto holders and developers by smuggling infostealers into open-source code repositories.


The Visual Studio Marketplace and the Open VSX Registry are both platforms for distributing extensions, with the former being Microsoft-owned and used in Visual Studio and Visual Studio Code, while the latter is a vendor-neutral, open-source alternative designed for VS Code-compatible editors like Eclipse Theia, Gitpod, SAP Business Application Studio, and others.



Similar Posts