Storyline
GlassWorm malware campaign escalates with new fake extensions in Open VSX marketplace
The GlassWorm threat actor has significantly increased its activity by uploading 73 additional fraudulent extensions to the Open VSX code marketplace.
Current brief openSource links open
This current storyline is open here with summary, metadata, source links, continuity context, and full evidence. Paid is for compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
The GlassWorm threat actor has significantly increased its activity by uploading 73 additional fraudulent extensions to the Open VSX code marketplace.
Score total
1
Momentum 24h
2
Posts
2
Origins
2
Source types
2
Duplicate ratio
50%
Why now
- Recent upload of 73 new fake extensions marks a significant escalation in activity.
- New extensions use advanced evasion techniques like bundled native binaries.
- Ongoing campaign continues to exploit trusted developer tool ecosystems.
Why it matters
- GlassWorm targets software supply chains, risking widespread developer and user compromise.
- The use of benign code initially helps evade detection, increasing infection success rates.
- Escalation in malicious extensions signals growing threat sophistication and persistence.
Continuity snapshot
- Trend status: insufficient_history.
- Continuity stage: emerging_confirmed.
- Current status: open.
- 2 current source-linked posts are attached to this storyline.
All evidence
All evidence
CSO Online - More fake extensions linked to GlassWorm found in Open VSX code marketplace
csoonline.com · csoonline.com · 2026-04-29 00:48 UTC
The Malware Factory: GLASSWORM Forensics in Open VSX
malware · blog.yeethsecurity.com · 2026-04-29 02:53 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- csoonline.com (1)
- malware (1)
Top origin domains (this list)
- csoonline.com (1)
- blog.yeethsecurity.com (1)