A fourth wave of the GlassWorm targets macOS developers via malicious extensions for VSCode/OpenVSX, which distribute modified (trojanized) versions of crypto wallet applications.
See also: Glassworm malware: New malicious VS Code packages

Extensions in the OpenVSX and Microsoft Visual Studio Marketplace extend the capabilities of a VS Code-compatible editor, adding development tools, language support, or themes that improve productivity.
The Microsoft Visual Studio Marketplace is the official extension store for Visual Studio Code, while OpenVSX acts as an open and vendor-neutral alternative, used primarily by developers who do not support or choose not to rely on Microsoft's proprietary marketplace.
The GlassWorm malware first appeared on marketplaces in October, hidden within malicious extensions that used "invisible" Unicode characters.
Once installed, the malware attempted to steal GitHub, npm , and OpenVSX, as well as cryptocurrency wallet data via multiple extensions. It also provided remote access via VNC and could route network traffic through the victim's system using a SOCKS proxy.
Despite public disclosure and increased security measures, GlassWorm reappeared in early November in OpenVSX and then again in early December in VS Code.
Koi Security researchers have identified a new GlassWorm campaign that exclusively targets macOS systems , unlike previous versions that focused only on Windows.
See also: How GlassWorm returned to developers' code

Unlike the "invisible" Unicode characters used in the first two waves or the compiled Rust binaries of the third, the most recent GlassWorm attacks leverage an AES-256-CBCembedded in compiled JavaScript within OpenVSX, such as:
- studio-velte-distributor.pro-svelte-extension
- cudra-production.vsce-prettier-pro
- Puccin-development.full-access-catppuccin-pro-extension
The malicious code is activated after a 15-minute delay, likely to avoid analysis in sandbox environments.
Instead of PowerShell , AppleScript is now used, while LaunchAgents are used instead of Registry modifications to maintain a permanent presence on the system . The command-and-control (C2) mechanism based on the Solana blockchain remains the same, with researchers also pointing out overlaps in the infrastructure.
In addition to attacking more than 50 crypto wallet extensions for browsers, as well as stealing developer credentials (GitHub, NPM) and browsing data, GlassWorm is now also attempting to steal passwords from the macOS Keychain
See also: ShadyPanda: 4.3 million Chrome and Edge users were hacked

Additionally, a new feature has been added that checks for hardware crypto wallet applications, such as Ledger Live and Trezor Suite, on the system and replaces them with infected versions. Developers who have installed any of the three extensions are advised to immediately remove them, change their GitHub passwords, revoke their NPM tokens, and check their system for signs of infection or proceed with a reinstall.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
