A new phase in the evolving GlassWorm has raised concerns among the developer community after 73 additional malicious extensions in the Open VSX marketplace. The incident, detected in April 2026, shows that attackers are significantly ramping up their tactics in the software supply chain, directly targeting tools used by millions of developers every day.

This new activity follows previous attacks in March 2026, when 72 similar malicious extensions. The continued increase in the number demonstrates an organized and escalating effort to infiltrate the software development ecosystem, with the aim of mass distribution of malicious code.
See also: FIRESTARTER backdoor targeted federal Cisco Firepower device
The strategy of “sleeper extensions” and the deception of developers
Central to the new attack is the tactic of so-called sleeper extensions, extensions that initially appear completely harmless. These packages are published on popular platforms by fake or new accounts and imitate well-known development tools, aiming to gain the trust of developers and increase their installations.
In practice, attackers create clones of existing extensions, copying icons, descriptions, and structure, but changing critical details like the publisher. This tactic allows malicious packages to "build credibility" before their actual payload is activated.
Open VSX extensions: How we get to the malicious payload
The most dangerous element of this approach is the time delay between installation and activation. Attackers do not activate the malicious code immediately. Instead, they wait until they have a sufficient user base and then push out updates that turn the extensions into attack vectors.
According to security data, at least six of the 73 new extensions have already been activated and are being used to distribute malware. This confirms that the campaign is not theoretical, but is already in an active exploitation phase.
See also: Over 10,000 Zimbra servers vulnerable to XSS attacks

Technical evolution of attack methods
The technical structure of the new extensions shows significant progress compared to previous versions. The malicious code is no longer easily detectable within the source code, as it operates as an external loader that retrieves payloads from remote sources.
Two main delivery methods have been identified. The first relies on native .node binaries, which are executed via simple JavaScript wrapper scripts and link to remote URLs to download additional installation files. The second uses heavily obfuscated JavaScript, which is dynamically decoded at runtime, making analysis extremely difficult for security tools.
This approach drastically reduces the likelihood of detection during static checks, which explains why the campaign managed to remain active for so long.
The role of trust in the development ecosystem
The incident highlights a structural problem in the software supply chain: reliance on trust. Developers often install extensions based on popularity, number of downloads, or similarity to known tools, without conducting deeper checks.
Platforms like Open VSX and ecosystems like GitHub have become critical distribution points, but at the same time they are also attractive targets for malicious actors who exploit the speed and open nature of open-source software.
Recommendations and need for stricter control
Security research groups warn that verifying the identity of publishers and carefully evaluating extensions is now a necessary practice. Checking the publisher's history, namespaces, and update activity can significantly reduce the risk of malware installation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Side-channel attacks on smart homes

At the same time, it is proposed to strengthen control mechanisms in extension markets, with automated detection of suspicious patterns and better cross-checking of publisher identities. The GlassWorm incident demonstrates that the software supply chain is no longer a secondary risk area, but one of the most active and sophisticated cyberattack areas today.
GlassWorm: Breach Indicators
- Native Installer Binaries (SHA256): 1b62b7c2ed7cc296ce821f977ef7b22bae59ef1dcdb9a34ae19467ee39bcf168.
- Downloaded VSIX Payload (SHA256): 97c275e3406ad6576529f41604ad138c5bdc4297d195bf61b049e14f6b30adfd.
- Malicious GitHub Hosting: github[.]com/SquadMagistrate10/wnxtgkih.
- Confirmed malicious extensions: outsidestormcommand. monochromator-theme, boulderzitunnel. vscode-buddies.
