The Glassworm campaign , first detected in October on the OpenVSX and Microsoft Visual Studio Marketplaces , is back for a third time with even more extensive activity. In its latest wave, 24 new malicious packages were detected , significantly increasing the scope of the threat to developers who rely on these repos to manage VS Code extensions.

What are OpenVSX and Microsoft Visual Studio Marketplace?
These marketplaces are central repositories for VS Code-compatible extensions. They are used by millions of developers looking for language support packages, frameworks, debugging tools, themes, and productivity add-ons.
- Visual Studio Marketplace: the official Microsoft ecosystem.
- OpenVSX: independent, vendor-neutral platform, ideal for projects outside the Microsoft environment.
The parallel targeting of both marketplaces makes Glassworm an extremely dangerous and unusual campaign, as it exploits both proprietary and open-source ecosystems equally.
See also: APT36 used Python ELF malware against the Indian government
How Glassworm works
The malware was first detected by Koi Security and is notable for its clever use of invisible Unicode characters, which hide executable malicious code within seemingly innocent packages. Once the extensions are installed, Glassworm attempts to steal:
- GitHub, npm, and OpenVSX accounts
- data from crypto wallets managed by developers through 49 different extensions
But the threat doesn't stop there. Glassworm installs a SOCKS proxyto route malicious traffic through the victim's computer, and adds an HVNC clientthat allows attackers to gain full remote access without leaving any visible traces.
Although the initial infections were “cleaned up,” the perpetrators quickly returned with new publisher accounts and fresh extensions, making it clear that the fight against them is still an ongoing battle.
The third wave of the attack: Even more targeted
The latest resurgence was uncovered by researcher John Tuckner of Secure Annex, who noted that the packages are named after popular developer tools: Flutter, Vim, Yaml, Tailwind, Svelte, React Native, Vue, and many more. This suggests that the attackers are targeting as broad a developer base as possible.
See also: Domain hijacking risk from old Python Bootstrap Scripts

Specifically, Secure Annex found that the third wave of attacks uses the following packages:
VS Marketplace
- iconkieftwo.icon-theme-materiall
- prisma-inc.prisma-studio-assistance
- prettier-vsc.vsce-prettier
- flutcode.flutter-extension
- csvmech.csvrainbow
- codevsce.codelddb-vscode
- saoudrizvsce.claude-devsce
- clangdcode.clangd-vsce
- cweijamysq.sync-settings-vscode
- bphpburnsus.iconesvscode
- klustfix.kluster-code-verify
- vims-vsce.vscode-vim
- yamlcode.yaml-vscode-extension
- solblanco.svetle-vsce
- vsceue.volar-vscode
- redmat.vscode-quarkus-pro
- msjsdreact.react-native-vsce
Open VSX
- bphpburn.icons-vscode
- tailwind-nuxt.tailwindcss-for-react
- flutcode.flutter-extension
- yamlcode.yaml-vscode-extension
- saoudrizvsce.claude-dev
- saoudrizvsce.claude-devsce
- vitalik.solidity
Secure Annex reports that the third wave is based on a “dual-phase” technique:
- Packages are initially published as harmless extensions to be approved.
- An update that introduces the malicious code follows .
At the same time, attackers artificially increase the number of downloads so that the extensions appear legitimate, leveraging marketplace ranking algorithms to rank high in search results.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
New techniques and advanced implants
One of the most worrying elements of the third wave is Glassworm's transition to Rust-based implants, which offer greater difficulty in analysis and stronger concealment. The Unicode character trick is still used, but it is now just one part of a more complex ecosystem of malicious modules.
See also: Delivery of malicious content via Apple Podcasts?

How are platforms reacting?
Microsoft said it is constantly improving its scanning systems marketplace and encourages users to use the “Report Abuse” on each extension page to help identify suspicious packages more quickly. OpenVSX has also implemented token renewals and additional checks, although the persistence of Glassworm shows that attackers are still finding new ways to circumvent it.
What should developers do?
Experts recommend:
- careful review of the publishers of each extension
- use of integrity checking tools in development environments
- avoiding installation of packages with sudden "burst" downloads
- continuous monitoring of tokens and developer accounts
The Glassworm case is a stark reminder that even the most everyday development tools can be transformed into invisible attack vectors.
Source: www.bleepingcomputer.com
