A month after the discovery of a self-replicating virus in the open source NPM repository, a similar worm has been detected targeting Visual Studio Code in open markets.
See also: Over 100 VS Code extensions expose developers

Researchers at Koi Securityreport that the malware, which they call GlassWorm, has been found in extensions in the OpenVSX and Microsoft VS Code. If the compromised extensions are embedded in code, they harvest NPM, GitHub , and Git left by developers at work, empty funds from 49 cryptocurrency wallets, deploy SOCKS proxy on developers' computers, install hidden VNX servers for remote access, and use the stolen credentials to compromise additional packages and extensions.
Seven OpenVSX extensions were compromised last week and downloaded more than 35,000 times, the report says. In addition, another infected extension was detected in the Visual Studio Code marketplace last weekend. The extension worms evade detection using an old technique: They include malware written in Unicode variants. These are special characters that are part of the Unicode specification but do not produce any visual output.
CISOs should begin incident response processes immediately, conducting an inventory to see which enterprise applications use VS Code, what extensions they contain, and determining if any are on the known affected list. They should also monitor for suspicious application behavior, especially strange outbound connections and processes mentioned in the investigation, unapproved VNC servers, and long-running SOCKS proxy processes.
See also: WhiteCobra: Malicious extensions in the VSCode market

Koi Security’s report is the latest in a series of warnings that threat actors are increasingly targeting Visual Studio Code marketplaces in supply chain attacks. Last week, Koi Security uncovered a threat actor called TigerJack that spreads malicious extensions. And Wiz researchers just published research showing widespread abuse of the OpenVSX and VS Code.
The use of Unicode to hide malware was recently exposed last month by researchers at Radware, who found it being used to compromise ChatGPT. These reports should come as no surprise. Open source marketplaces, where developers can upload code for others to use in their applications, have long been targets for threat actors as vehicles for introducing malicious code into projects. The code is then spread to developer or customer environments to steal credentials and data.
Microsoft gives developers the ability to add extensions and themes to Visual Studio Code to make developers' lives easier, as well as enhance functionality. An extension can add features like debuggers, new languages, or other development tools, while a theme is a type of extension that changes the appearance of the editor, controlling things like colors and fonts.
See also: Contagious Interview: Attack with 338 malicious npm packages

Developers are a prime target for attacks these days, says Johannes Ullrich, dean of research at the SANS Institute. What they often don't realize is that any extension they install, even if it seems harmless, has full access to their code and can make modifications without explicitly notifying the developer. CISOs should include developers in discussions about the security of development tools, he advises.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
