Security Threats Emerge from Malicious and AI-Generated Extensions on Developer Platforms

TL;DR
Cybersecurity researchers have identified three malicious VS Code extensions linked to the GlassWorm campaign, which uses invisible Unicode characters to hide malware, steal credentials, and spread in a worm-like fashion. Despite removal efforts, the threat has resurfaced, leveraging blockchain-based command-and-control infrastructure to maintain resilience. The attack has affected victims worldwide, including a major Middle Eastern government, and has expanded to target GitHub repositories.
Topics:technologycybersecurity#credential-theft#cyberattack#cybersecurity#glassworm#malware#vs-code-extensions
- GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs The Hacker News
- Vibe-coded ransomware proof-of-concept ended up on Microsoft’s marketplace csoonline.com
- AI-Created Malicious VS Code Extension and Trojanized npm Packages Raise New Supply Chain Security Concerns CXO Digitalpulse
- 3 VS Code extensions stealing credentials for GitHub, VSX, and crypto wallets Cryptopolitan
- AI-generated ransomware extension found on Visual Studio Marketplace SC Media
Want the full story? Read the original reporting
Read on The Hacker News