The GlassWorm campaign targeting Open VSX has escalated with 73 newly identified impersonation extensions. These sleeper extensions were initially published without malicious payloads by newly created GitHub accounts, appearing benign to build trust and credibility. At least six extensions have been activated to deliver malware through normal update mechanisms. The extensions clone popular legitimate listings with similar branding, icons, and descriptions, making detection difficult. The threat actor has shifted delivery methods away from embedded loaders toward transitive delivery via extension dependencies, external payload retrieval from GitHub-hosted VSIX files, and native binary execution. Some variants use obfuscated JavaScript to decode and retrieve payloads at runtime. The malicious code targets multiple IDEs including VS Code, Cursor, Windsurf, and VSCodium, installing downloaded extensions through command-line interfaces.
Executive Summary
GlassWorm is an APT‑style supply‑chain campaign that compromises the Open VSX extension marketplace to distribute malicious VS Code extensions. By publishing benign‑looking extensions that later activate hidden payloads, the group evades traditional detection and gains footholds on developers' workstations across multiple IDEs.
Goals & Targeting
GlassWorm appears to pursue strategic espionage objectives, seeking to infiltrate development environments to exfiltrate source code, intellectual property, and potentially embed long‑term backdoors for future operations. By focusing on popular IDEs and their extension ecosystems, the group maximizes reach across software‑heavy sectors such as technology, finance, and research. Typical victims are developers, DevOps engineers, and security‑aware organizations that trust open‑source marketplaces, making the campaign especially effective against enterprises with large development teams.
Enhanced Description
The GlassWorm operation targets the Open VSX ecosystem, leveraging the popularity of Visual Studio Code and related IDEs such as Cursor, Windsurf, and VSCodium. The adversary creates new GitHub accounts to publish extensions that initially contain no malicious code, establishing credibility and avoiding immediate scrutiny. After a period of trust building, at least six of these extensions switch to a sleeper mode, delivering malware through the standard extension update process. These malicious extensions are crafted to closely mimic legitimate listings, copying branding, icons, and descriptions to blend in with authentic offerings. Rather than embedding a loader directly, GlassWorm now employs a transitive delivery model: the compromised extension declares dependencies on additional malicious VSIX packages hosted on GitHub. When the victim’s IDE resolves these dependencies, it automatically downloads and installs the payload. The payload retrieval stage often uses obfuscated JavaScript that decodes at runtime and fetches binary components from the attacker‑controlled GitHub repository. Once downloaded, the binaries are executed via the IDE’s command‑line interface, granting the adversary execution rights on the developer’s machine. This approach enables the group to target a wide range of development environments while remaining under the radar of conventional anti‑malware solutions. GlassWorm’s tactics demonstrate a sophisticated understanding of modern software‑supply‑chain dynamics, exploiting trust in open‑source extension marketplaces and the automated update mechanisms that developers rely on daily. The campaign’s modular design allows rapid iteration of new malicious extensions, making it a persistent threat to organizations that depend on these development tools.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GlassWorm has operated intermittently since at least early 2023, with a noticeable escalation in mid‑2024 when the group introduced 73 new impersonation extensions. The campaign’s tempo is characterized by bursts of new extension releases followed by periods of dormant activity, allowing the malicious code to evade rapid detection. Victim analysis shows a concentration in North America and Europe, particularly targeting software development firms, fintech companies, and research institutions. Notable incidents include the compromise of a major open‑source library’s VS Code extension, which resulted in the theft of proprietary code from several downstream projects.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a high level of confidence regarding GlassWorm's tactics, techniques, and target ecosystem, as it is based on multiple observed malicious extensions and corroborating GitHub activity. However, gaps remain in attribution (specific nation‑state or group affiliation) and the full extent of the payload capabilities. Additional telemetry from compromised environments would improve confidence in the actor's ultimate objectives and any lateral movement tactics employed post‑infection.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
14
IOCs
0
Observed Data
0
Tactics