Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm

Posted on February 2, 2026February 2, 2026 By CWS

Ravie LakshmananFeb 02, 2026Developer Instruments / Malware

Cybersecurity researchers have disclosed particulars of a provide chain assault focusing on the Open VSX Registry by which unidentified risk actors compromised a respectable developer’s sources to push malicious updates to downstream customers.
“On January 30, 2026, 4 established Open VSX extensions revealed by the oorzc writer had malicious variations revealed to Open VSX that embed the GlassWorm malware loader,” Socket safety researcher Kirill Boychenko stated in a Saturday report.
“These extensions had beforehand been introduced as respectable developer utilities (some first revealed greater than two years in the past) and collectively gathered over 22,000 Open VSX downloads previous to the malicious releases.”
The provision chain safety firm stated that the provision chain assault concerned the compromise of the developer’s publishing credentials, with the Open VSX safety group assessing the incident as involving using both a leaked token or different unauthorized entry. The malicious variations have since been faraway from the Open VSX.

The checklist of recognized extensions is under –

FTP/SFTP/SSH Sync Device (oorzc.ssh-tools — model 0.5.1)
I18n Instruments (oorzc.i18n-tools-plus — model 1.6.8)
vscode mindmap (oorzc.mind-map — model 1.0.61)
scss to css (oorzc.scss-to-css-compile — model 1.3.4)

The poisoned variations, Socket famous, are designed to ship a loader malware related to a identified marketing campaign referred to as GlassWorm. The loader is provided to decrypt and run embedded at runtime, makes use of an more and more weaponized method referred to as EtherHiding to fetch command-and-control (C2) endpoints, and finally run code designed to steal Apple macOS credentials and cryptocurrency pockets information.

On the identical time, the malware is detonated solely after the compromised machine has been profiled, and it has been decided that it doesn’t correspond to a Russian locale, a sample generally noticed in malicious applications originating from or affiliated with Russian-speaking risk actors to keep away from home prosecution.
The sorts of knowledge harvested by the malware embody –

Information from Mozilla Firefox and Chromium-based browsers (logins, cookies, web historical past, and pockets extensions like MetaMask)
Cryptocurrency pockets information (Electrum, Exodus, Atomic, Ledger Stay, Trezor Suite, Binance, and TonKeeper)
iCloud Keychain database
Safari cookies
Information from Apple Notes
consumer paperwork from Desktop, Paperwork, and Downloads folders
FortiClient VPN configuration information
Developer credentials (e.g., ~/.aws and ~/.ssh)

The focusing on of developer info poses extreme dangers because it exposes enterprise environments to potential cloud account compromise and lateral motion assaults.

“The payload contains routines to find and extract authentication materials utilized in widespread workflows, together with inspecting npm configuration for _authToken and referencing GitHub authentication artifacts, which may present entry to personal repositories, CI secrets and techniques, and launch automation,” Boychenko stated.
A major facet of the assault is that it diverges from beforehand noticed GlassWorm indicators in that it makes use of a compromised account belonging to a respectable developer to distribute the malware. In prior cases, the risk actors behind the marketing campaign have leveraged typosquatting and brandjacking to add fraudulent extensions for subsequent propagation.
“The risk actor blends into regular developer workflows, hides execution behind encrypted, runtime-decrypted loaders, and makes use of Solana memos as a dynamic lifeless drop to rotate staging infrastructure with out republishing extensions,” Socket stated. “These design selections cut back the worth of static indicators and shift defender benefit towards behavioral detection and speedy response.”

The Hacker News Tags:Account, Attack, Chain, Compromised, Dev, GlassWorm, Open, Spread, Supply, VSX

Post navigation

Previous Post: State-Sponsored Actors Hijacked Notepad++ Update to Redirect Users to Malicious Servers
Next Post: eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware

Related Posts

Eclipse Foundation Enhances Security for VS Code Extensions Eclipse Foundation Enhances Security for VS Code Extensions The Hacker News
84 Security Flaws Uncovered in 4G and 5G Networks 84 Security Flaws Uncovered in 4G and 5G Networks The Hacker News
LiteLLM Attack Exploits Developer Machines for Credentials LiteLLM Attack Exploits Developer Machines for Credentials The Hacker News
Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks The Hacker News
Bridging the Remediation Gap: Introducing Pentera Resolve Bridging the Remediation Gap: Introducing Pentera Resolve The Hacker News
Zbtlink Routers Expose Security Flaw with Built-in Backdoor Zbtlink Routers Expose Security Flaw with Built-in Backdoor The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark