๐จ ๐๐ฟ๐ฒ๐ฎ๐ธ๐ถ๐ป๐ด: ๐ช๐ฒ'๐๐ฒ ๐ฑ๐ถ๐๐ฐ๐ผ๐๐ฒ๐ฟ๐ฒ๐ฑ ๐๐ต๐ฒ ๐๐ผ๐ฟ๐น๐ฑ'๐ ๐ณ๐ถ๐ฟ๐๐ ๐๐ฒ๐น๐ณ-๐ฝ๐ฟ๐ผ๐ฝ๐ฎ๐ด๐ฎ๐๐ถ๐ป๐ด ๐๐ผ๐ฟ๐บ ๐๐ฎ๐ฟ๐ด๐ฒ๐๐ถ๐ป๐ด ๐ฉ๐ฆ ๐๐ผ๐ฑ๐ฒ ๐ฒ๐
๐๐ฒ๐ป๐๐ถ๐ผ๐ป๐. ๐ญ๐ฌ,๐ณ๐ญ๐ญ ๐ฑ๐ฒ๐๐ฒ๐น๐ผ๐ฝ๐ฒ๐ฟ๐ ๐ถ๐ป๐ณ๐ฒ๐ฐ๐๐ฒ๐ฑ. ๐๐ถ๐๐ฒ ๐ฒ๐
๐๐ฒ๐ป๐๐ถ๐ผ๐ป๐ ๐๐๐ถ๐น๐น ๐ฎ๐ฐ๐๐ถ๐๐ฒ.
Meet GlassWorm - just one month after Shai Hulud became the first worm in npm, we're seeing the same autonomous spreading technique hit OpenVSX. But this attack is on another level.
Here's what makes GlassWorm unprecedented:
๐ญ. ๐๐ป๐๐ถ๐๐ถ๐ฏ๐น๐ฒ ๐ฐ๐ผ๐ฑ๐ฒ - The malware uses unprintable Unicode characters to hide itself. You literally can't see it in your code editor. Code review? Useless. Static analysis? Blind.
๐ฎ. ๐๐น๐ผ๐ฐ๐ธ๐ฐ๐ต๐ฎ๐ถ๐ป ๐๐ฎ - Uses Solana blockchain transactions as command infrastructure. Can't be taken down. Can't be censored. Updates cost less than a penny.
๐ฏ. ๐๐๐น๐น ๐ฅ๐๐ง - Deploys SOCKS proxies, hidden VNC servers, WebRTC P2P, and BitTorrent DHT. Turns your developer workstation into criminal infrastructure with complete remote access.
๐ฐ. ๐ฆ๐ฒ๐น๐ณ-๐ฝ๐ฟ๐ผ๐ฝ๐ฎ๐ด๐ฎ๐๐ถ๐ป๐ด - Steals NPM, GitHub, and OpenVSX credentials to automatically compromise more packages. Each infection spawns more infections.
Seven extensions were compromised on October 17th. The attack is active right now - C2 servers responding, credentials being harvested, and the worm is spreading using stolen tokens.
Affected extensions:
๐ codejoy.codejoy-vscode-extension
๐ l-igh-t.vscode-theme-seti-folder
๐ kleinesfilmroellchen.serenity-dsl-syntaxhighlight
๐ JScearcy.rust-doc-viewer
๐ SIRILMP.dark-theme-sm
๐ CodeInKlingon.git-worktree-menu
๐ ginfuru.better-nunjucks
๐ง๐ต๐ฒ ๐ฟ๐ฒ๐ฎ๐น ๐ถ๐๐๐๐ฒ? Extension marketplaces have no behavioral monitoring. Malicious code auto-updates silently. By the time anyone notices, the worm has already spread.
This is the new normal for supply chain attacks - self-sustaining, invisible, and nearly impossible to stop with traditional security tools.