Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
leaked-secret-api-keyextension-plugin-hijackvendor-distribution-compromisepackage-repository-poisoning

Open VSX Token Exposure and GlassWorm Supply Chain Attack

Updated 3mo agoFirst seen Oct 31, 202512 sources

Eclipse Foundation revoked a small number of leaked access tokens for the Open VSX extension marketplace after a report from Wiz revealed that several Visual Studio Code extensions had inadvertently exposed their tokens in public repositories. This exposure could have allowed attackers to take control of extensions and distribute malware, posing a significant supply chain risk. The foundation confirmed that the leaks were due to developer mistakes, not a compromise of Open VSX infrastructure, and has since implemented new security measures, including a token prefix format and reduced token lifetimes. Additionally, extensions flagged as part of the "GlassWorm" campaign by Koi Security were removed, and the foundation clarified that the reported download numbers were likely inflated by bots and threat actor tactics.

The GlassWorm campaign involved the use of hidden malicious code injected with invisible Unicode Private Use Area (PUA) characters, a technique previously observed in npm packages and now seen in compromised Open VSX extensions. Security researchers noted that the same threat actor has shifted focus to GitHub repositories, using increasingly stealthy methods to inject malware into legitimate-looking commits. The campaign highlights the evolving tactics of supply chain attackers and the importance of proactive security measures in open-source ecosystems.

Share:
Open VSX Token Exposure and GlassWorm Supply Chain Attack
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Nov 10, 20257mo ago

Law enforcement receives data tied to GlassWorm infrastructure

Researchers provided law enforcement with additional information related to cryptocurrency exchanges and messaging platforms allegedly involved in the GlassWorm operation. This marked an escalation from technical reporting to active information-sharing for possible enforcement action.

Threat actor linked to Russian-speaking operators and RedExt framework

Technical analysis published on November 10, 2025 attributed the GlassWorm activity to a likely Russian-speaking threat actor. Researchers said the operation used the open-source RedExt browser-extension command-and-control framework and blockchain-based infrastructure to update C2 details.

Researchers report GlassWorm resurgence and wider victim impact

By November 10, 2025, multiple reports said the renewed campaign had affected at least 60 organizations worldwide, including a major Middle Eastern government entity. Researchers also described the malware as using stolen GitHub, Git, and npm credentials to spread into repositories and maintain persistence.

Nov 6, 20258mo ago

Three new Open VSX extensions are compromised by GlassWorm

On November 6, 2025, researchers found three additional malicious VS Code extensions on Open VSX, showing that the campaign had resurfaced despite earlier token revocations. These extensions added about 10,000 more downloads to the operation and reused the same invisible-Unicode obfuscation technique.

Oct 31, 20258mo ago

Researchers find GlassWorm has shifted to GitHub JavaScript projects

Aikido researchers reported a new wave of attacks on GitHub JavaScript repositories using hidden Unicode Private Use Area characters to conceal malicious code. The campaign, tied to the same actor behind the npm and Open VSX incidents, used stolen credentials and Solana-hosted payload delivery, raising concerns about worm-like propagation.

Eclipse Foundation revokes and rotates compromised Open VSX tokens

Following the discovery of leaked tokens, the Eclipse Foundation/Open VSX team removed malicious extensions and revoked or rotated compromised access tokens to contain the attack. The registry also began planning additional protections such as shorter token lifetimes, faster revocation, and automated extension scanning.

Wiz discovers hundreds of leaked marketplace and Open VSX secrets

Wiz researchers identified more than 550 exposed secrets across the Microsoft VS Code and Open VSX extension ecosystems, including tokens that could be abused to publish malicious extensions. This discovery linked leaked developer credentials to the ongoing GlassWorm supply-chain activity.

Oct 15, 20258mo ago

GlassWorm campaign compromises Open VSX extensions in mid-October

By mid-October 2025, the broader GlassWorm supply-chain campaign had already compromised about a dozen VS Code/Open VSX extensions, generating roughly 35,000 downloads. The malware used invisible Unicode characters to hide JavaScript payloads that stole developer credentials and cryptocurrency-related data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Affected products
4 linked
GithubVisual Studio CodeGithubNpm
Organizations
9 linked
Koi SecurityMicrosoft CorporationAikido SecurityGitHubOpen VSXBleepingComputerSecurity AffairsEclipse FoundationWiz
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Open VSX Token Exposure and GlassWorm Supply Chain Attack | Mallory