The GlassWorm has evolved into one of the most sophisticated supply chain threats targeting developers, with cybersecurity researchers identifying at least 72 malicious extensions in the Open VSX registry. The new version of the campaign represents a “significant escalation” in its distribution, as attackers now use extensionPack and extensionDependencies to turn seemingly innocent extensions into malware delivery vehicles.

According to security firm Socket, instead of requiring each malicious entry to directly embed the loader, attackers are now exploiting the relationships between extensions. This tactic allows a seemingly innocent package to start pulling a separate GlassWorm-linked extension only after users' trust has already been established.
See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account
The malicious extensions mimic widely used developer tools, including linters and formatters, code runners, and tools for AI-powered coding assistants like Claude Code and Google Antigravity. Extensions removed from the registry include: angular-studio.ng-angular-extension, crotoapp.vscode-xml-extension, gvotcha.claude-code-extension, and mswincx.antigravity-cockpit.
Evolution of the GlassWorm campaign and new tactics
The GlassWorm began in October 2025, when Koi Security detected suspicious behavior in the CodeJoy (version 1.8.3), revealing a self-propagating worm that used invisible Unicode characters to hide malicious payloads. The initial attack contributed to over 35,800 downloads and affected seven extensions in Open VSX.
The new version retains many of the features associated with GlassWorm: it performs checks to avoid infecting systems with a Russian locale and uses Solana transactions as a dead drop resolver to retrieve the command-and-control (C2) server. However, the new set of extensions features stronger obfuscation and rotates Solana wallets to avoid detection. It also abuses extension relationships to deploy malicious payloads. Regardless of whether an extension is declared as “extensionPack” or “extensionDependencies” in the extension’s “package.json” file, the processor proceeds to install any other extensions that reference it.

In this way, the GlassWorm campaign uses an extension as an installer for another extension that is malicious. This also opens up new attack scenarios in the supply chain, as an attacker first uploads a completely harmless VS Code extension to the marketplace to bypass the review. Then, an update appears to list a package that links to GlassWorm as a dependency.
See also: New malicious packages revealed in NuGet Supply Chain Attack
“As a result, an extension that seemed non-transitory and comparatively harmless upon initial publication can later become a GlassWorm delivery vehicle without any change to its apparent purpose,” Socket said.
In a new advisory, Aikido has linked the GlassWorm threat actor to a massive campaign spreading across open-source repositories, with attackers inserting invisible Unicode characters into various repositories to encode a payload. While the content is not visible when loaded into code editors and terminals, it is decoded into a loader that is responsible for retrieving and executing a second-stage script to stealtokens, credentials, and secrets.
It is estimated that at least 151 GitHub repositories have been affected, as part of this campaign, between March 3 and March 9, 2026. Furthermore, the same Unicode technique has been deployed in two different npm packages, indicating a coordinated, cross-platform push –
@aifabrix/miso-client
@iflow-mcp/watercrawl-watercrawl-mcp

Impact and protection recommendations
The GlassWorm represents a fundamental shift in supply chain attack tactics, as it turns standalone extensions into transitive delivery vehicles after updates. This creates new attack scenarios where an attacker can first upload a completely innocent VS Code extension to bypass the revision, and then update it to include a GlassWorm-linked package as a dependency.
See also: Supply Chain Threat Protection: New security solution from SpyCloud
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The researchers recommend that developers disable automatic updates for VS Code extensions and regularly check installed extensions for suspicious network activity or access to credentials. Additionally, they should monitor npm and GitHub tokens , as well as their cryptocurrency wallets for unauthorized activity.
The Eclipse Foundation and the Open VSX registry have taken steps to remove malicious extensions and disable compromised accounts. However, the ongoing campaign highlights the need for more advanced detection and protection methods in the developer tools ecosystem.
