Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
package-repository-poisoningextension-plugin-hijackdetection-content-updatevendor-distribution-compromise

GlassWorm Supply-Chain Worm Hits VS Code, OpenVSX, npm, PyPI, and GitHub

Updated 23d agoFirst seen May 25, 202613 sources

GlassWorm was reported as a self-propagating supply-chain malware campaign that spread through developer ecosystems including the VS Code Marketplace, OpenVSX, npm, PyPI, and GitHub repositories. Reporting indicates the malware abused invisible Unicode characters to hide malicious logic inside extensions and packages, allowing payloads to evade casual review while embedding decoder routines, command-and-control markers, and other indicators of compromise. One wave specifically targeted macOS users through poisoned OpenVSX extensions, expanding the campaign beyond code repositories into developer workstations.

Security researchers and defenders responded by publishing detection guidance and tooling to hunt for GlassWorm artifacts across local Git repositories, VS Code extensions, and package dependencies. The open-source glassworm-hunter project was released to scan for hidden Unicode payloads, decoder patterns, C2 markers, and known malicious IOCs, reflecting concern that the campaign crossed multiple software distribution channels rather than a single marketplace. The incident highlights a broad software supply-chain intrusion in which trusted developer platforms were used to distribute stealthy malware concealed inside seemingly legitimate code.

Share:
GlassWorm Supply-Chain Worm Hits VS Code, OpenVSX, npm, PyPI, and GitHub
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
May 27, 202627d ago

Researchers link GlassWorm to PyPI and hijacked React Native npm packages

CrowdStrike and Sonatype linked the GlassWorm campaign to activity involving PyPI repositories and hijacked React Native npm packages with more than 30,000 weekly downloads. The reporting also described Solana blockchain-based command-and-control and additional credential- and wallet-theft capabilities, expanding the known scope and tradecraft of the campaign.

Developer-Targeting Glassworm Malware Abuses npm, PyPI, OpenVSX, and GitHub

OSV withdraws 157 likely automated false-positive malware reports

One day after the GlassWorm takedown, the OSV database withdrew 157 malware reports after maintainers concluded the submissions were likely automated false positives. The development was reported in the context of growing noise around supply-chain security reporting.

Supply chain battles intensify as takedowns meet AI-driven noise | InfoWorld

CrowdStrike attributes GlassWorm to Russian threat actors

Following reporting on the coordinated disruption of GlassWorm, CrowdStrike said the operation was likely conducted by Russian threat actors. The attribution was based on CIS-avoidance logic, Russian-language comments in the malware, and broader tradecraft patterns.

How cybersecurity firms took down Glassworm botnet in one shot

Coordinated takedown disrupts GlassWorm command-and-control channels

CrowdStrike, working with Google and the Shadowserver Foundation, announced a coordinated disruption of all four command-and-control channels used by the GlassWorm campaign. The report said the operation targeted resilient infrastructure including Solana blockchain, BitTorrent DHT, Google Calendar, and VPS-hosted channels supporting the developer-focused supply-chain malware.

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
Apr 3, 20263mo ago

Glassworm-hunter tool released to scan for GlassWorm indicators

A public GitHub tool, glassworm-hunter, was released to detect GlassWorm indicators in VS Code extensions, npm and PyPI packages, and local Git repositories. The tool searches for invisible Unicode payloads, decoder patterns, command-and-control markers, and known malicious IOCs.

Mar 16, 20263mo ago

OpenSource Malware details GlassWorm spread across GitHub, npm, Open VSX and VS Code

Technical analysis expanded the known scope of the GlassWorm campaign, describing activity across GitHub repositories, npm packages, Open VSX, and VS Code. The report characterized the operation as a multi-platform supply-chain intrusion using related tactics across ecosystems.

Feb 3, 20265mo ago

TechRadar reports GlassWorm targeting macOS via OpenVSX extensions

Reporting highlighted that GlassWorm was being used to target macOS users through malicious OpenVSX extensions. The coverage framed the activity as an active malware threat delivered through the extension marketplace.

Oct 18, 20258mo ago

GlassWorm worm first hits Open VSX and VS Code extension ecosystems

GlassWorm was identified as a self-propagating supply-chain worm affecting the Open VSX and VS Code extension ecosystems. Early reporting described invisible-code techniques and malicious extension propagation as the core of the campaign.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Threat actors
3 linked
Affected products
7 linked
Visual Studio CodeCursorChromeWindsurfGithubCursorNpm
Organizations
16 linked
CrowdStrikeGoogleShadowServer FoundationGitHubMicrosoft CorporationEndor LabsKoi SecurityThe RegisterLinkedinTechCrunchSonatypeVultrOpenaiXnpm, Inc.Security Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

GlassWorm Supply-Chain Worm Hits VS Code, OpenVSX, npm, PyPI, and GitHub | Mallory