Worm Attack Hits VS Code Extension Marketplaces
A self-propagating malware dubbed “GlassWorm” has infiltrated extensions in the Visual Studio Code and OpenVSX marketplaces, stealing developer credentials, draining crypto wallets, installing SOCKS proxies and remote-access trojans, and using hidden Unicode characters to evade detection. Researchers describe it as one of the most advanced supply-chain attacks to date. They urge companies to treat it as an active incident: audit installed extensions, block untrusted marketplaces, revoke compromised credentials, and monitor developer machines for anomalous connections.
Comments
Post a Comment