Close Menu
TechurzTechurz
    What's Hot

    Anthropic’s latest feud with the Trump admin may actually help it, sales data suggests

    June 16, 2026

    This startup’s super metals could soon be in military drones, luxury watches, and chef’s knives

    June 16, 2026

    Probably raises $9M to build a more reliable kind of AI

    June 16, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Anthropic’s latest feud with the Trump admin may actually help it, sales data suggests
    • This startup’s super metals could soon be in military drones, luxury watches, and chef’s knives
    • Probably raises $9M to build a more reliable kind of AI
    • Payments startup Flutterwave hits $3.2B valuation, backed by Ripple
    • Malaysia’s AI agent-powered messaging app Respond.io raises $62.5M, eyes acquisitions
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Self-Spreading ‘GlassWorm’ Infects VS Code Extensions in Widespread Supply Chain Attack
    Cyber Reality

    Self-Spreading ‘GlassWorm’ Infects VS Code Extensions in Widespread Supply Chain Attack

    TechurzBy TechurzOctober 24, 2025Updated:May 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Supply Chain Attack
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 24, 2025Ravie LakshmananDevOps / Malware

    Cybersecurity researchers have discovered a self-propagating worm that spreads via Visual Studio Code (VS Code) extensions on the Open VSX Registry and the Microsoft Extension Marketplace, underscoring how developers have become a prime target for attacks.

    The sophisticated threat, codenamed GlassWorm by Koi Security, is the second such supply chain attack to hit the DevOps space within a span of a month after the Shai-Hulud worm that targeted the npm ecosystem in mid-September 2025.

    What makes the attack stand out is the use of the Solana blockchain for command-and-control (C2), making the infrastructure resilient to takedown efforts. It also uses Google Calendar as a C2 fallback mechanism.

    Another novel aspect is that the GlassWorm campaign relies on “invisible Unicode characters that make malicious code literally disappear from code editors,” Idan Dardikman said in a technical report. “The attacker used Unicode variation selectors – special characters that are part of the Unicode specification but don’t produce any visual output.”

    The end goal of the attack is to harvest npm, Open VSX, GitHub, and Git credentials, drain funds from 49 different cryptocurrency wallet extensions, deploy SOCKS proxy servers to turn developer machines into conduits for criminal activities, install hidden VNC (HVNC) servers for remote access, and weaponize the stolen credentials to compromise additional packages and extensions for further propagation.

    The names of the infected extensions, 13 of them on Open VSX and one on the Microsoft Extension Marketplace, are listed below. These extensions have been downloaded about 35,800 times. The first wave of infections took place on October 17, 2025. It’s currently not known how these extensions were hijacked.

    • codejoy.codejoy-vscode-extension 1.8.3 and 1.8.4
    • l-igh-t.vscode-theme-seti-folder 1.2.3
    • kleinesfilmroellchen.serenity-dsl-syntaxhighlight 0.3.2
    • JScearcy.rust-doc-viewer 4.2.1
    • SIRILMP.dark-theme-sm 3.11.4
    • CodeInKlingon.git-worktree-menu 1.0.9 and 1.0.91
    • ginfuru.better-nunjucks 0.3.2
    • ellacrity.recoil 0.7.4
    • grrrck.positron-plus-1-e 0.0.71
    • jeronimoekerdt.color-picker-universal 2.8.91
    • srcery-colors.srcery-colors 0.3.9
    • sissel.shopify-liquid 4.0.1
    • TretinV3.forts-api-extention 0.3.1
    • cline-ai-main.cline-ai-agent 3.1.3 (Microsoft Extension Marketplace)

    The malicious code concealed within the extensions is designed to search for transactions associated with an attacker-controlled wallet on the Solana blockchain, and if found, it proceeds to extract a Base64-encoded string from the memo field that decodes to the C2 server (“217.69.3[.]218” or “199.247.10[.]166”) used for retrieving the next-stage payload.

    The payload is an information stealer that captures credentials, authentication tokens, and cryptocurrency wallet data, and reaches out to a Google Calendar event to parse another Base64-encoded string and contact the same server to obtain a payload codenamed Zombi. The data is exfiltrated to a remote endpoint (“140.82.52[.]31:80”) managed by the threat actor.

    Written in JavaScript, the Zombi module essentially turns a GlassWorm infection into a full-fledged compromise by dropping a SOCKS proxy, WebRTC modules for peer-to-peer communication, BitTorrent’s Distributed Hash Table (DHT) for decentralized command distribution, and HVNC for remote control.

    The problem is compounded by the fact that VS Code extensions are configured to auto-update, allowing the threat actors to push the malicious code automatically without requiring any user interaction.

    “This isn’t a one-off supply chain attack,” Dardikman said. “It’s a worm designed to spread through the developer ecosystem like wildfire.”

    “Attackers have figured out how to make supply chain malware self-sustaining. They’re not just compromising individual packages anymore – they’re building worms that can spread autonomously through the entire software development ecosystem.”

    The development comes as the use of blockchain for staging malicious payloads has witnessed a surge due to its pseudonymity and flexibility, with even threat actors from North Korea leveraging the technique to orchestrate their espionage and financially motivated campaigns.

    Attack Chain code extensions GlassWorm Infects SelfSpreading Supply Widespread
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFormel 1 betroffen: Cyberattacke auf Fahrer-Portal
    Next Article The best laptops under $1,000 of 2025: Expert tested and reviewed
    Techurz
    • Website

    Related Posts

    Cyber Reality

    Digital Identity Protection: 7 Hidden Risks Most Users Miss

    May 25, 2026
    Cyber Reality

    Neural Data Policy: 7 Risks That Brain Privacy Laws Miss

    May 25, 2026
    Cyber Reality

    How AI Changing Cyber Crime: 7 Critical Shifts to Watch

    May 25, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,289

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622

    Future of Digital Privacy and Security: 7 Truths Nobody Tells You

    May 25, 202619
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.