Hacking

GlassWorm Malware Strikes VS Code and GitHub Again

Published  ·  2 min read
Updated on November 10, 2025

A new chapter in the GlassWorm saga is unfolding, putting developers on high alert. Researchers have identified three VS Code extensions linked to the campaign that remain downloadable:

  1. ai-driven-dev.ai-driven-dev (3,402 downloads)
  2. adhamu.history-in-sublime-merge (4,057 downloads)
  3. yasuyuky.transient-emacs (2,431 downloads)

GlassWorm first appeared last month. It targets VS Code extensions on the Open VSX Registry and Microsoft Marketplace. Once installed, it can steal Open VSX, GitHub, and cryptocurrency wallet credentials. In some cases, it drains funds from nearly 50 different wallets.

The malware is clever. It hides code using invisible Unicode characters, making detection difficult. Stolen credentials let it compromise more extensions, allowing it to spread like a worm.

Open VSX removed the malicious extensions and rotated affected tokens on October 21, 2025. But the threat has returned. Researchers warn the same Unicode trick is being used again to slip past defenses.

Idan Dardikman, Yuval Ronen, and Lotan Sery explained, “The attacker posted a new transaction to the Solana blockchain with an updated command-and-control endpoint. Even if servers are shut down, infected machines fetch the new payload automatically.”

Investigators also discovered an exposed server endpoint, revealing victims across the U.S., South America, Europe, and Asia. A major Middle Eastern government organization is among those affected.

Keylogger data from the attacker’s machine suggests they are Russian-speaking and use an open-source C2 framework called RedExt.

“These are real people and organizations affected by stolen credentials. Their machines could already be part of a criminal proxy network, and internal systems may be compromised,” Koi Security noted.

The threat is growing. Aikido Security reports that GlassWorm now targets GitHub repositories, pushing malicious commits using stolen credentials.

Developers need to stay vigilant. Check extensions carefully, protect credentials, and monitor code repositories closely. GlassWorm shows that even widely trusted tools can be exploited to spread malware.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067