{"id":12408,"date":"2026-04-26T10:04:21","date_gmt":"2026-04-26T10:04:21","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/26\/73-open-vsx-sleeper-extensions-linked-to-glassworm-activate-new-malware-campaign\/"},"modified":"2026-04-26T10:04:21","modified_gmt":"2026-04-26T10:04:21","slug":"73-open-vsx-sleeper-extensions-linked-to-glassworm-activate-new-malware-campaign","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/26\/73-open-vsx-sleeper-extensions-linked-to-glassworm-activate-new-malware-campaign\/","title":{"rendered":"73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign"},"content":{"rendered":"<p>    73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/glassworm-infiltrated-vsx-extensions\/\" target=\"_blank\" rel=\"noreferrer noopener\">GlassWorm supply chain attack<\/a> targeting the Open VSX marketplace has escalated with the discovery of 73 new \u201csleeper\u201d extensions.<\/p>\n<p>Identified in April 2026, this cluster marks a dangerous shift in how threat actors distribute malware to software developers.<\/p>\n<p>This activity follows a major wave discovered in March 2026, where researchers documented <a href=\"https:\/\/cybersecuritynews.com\/glassworm-campaign-uses-72-malicious-open-vsx-extensions\/\" target=\"_blank\" rel=\"noreferrer noopener\">72 malicious Open VSX extensions<\/a> tied to the GlassWorm operation.<\/p>\n<p>Earlier variants abused extension dependency features to install malicious loaders silently. However, the new April 2026 cluster shows that attackers are evolving their tactics to evade security scans.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-sleeper-extension-strategy\"><strong>The Sleeper Extension Strategy<\/strong><\/h2>\n<p>A sleeper extension is a fake package published by threat actors before it is weaponized. These extensions initially appear harmless to build visual trust, gain credibility, and gather downloads.<\/p>\n<p>Attackers use newly created GitHub accounts to publish cloned versions of popular tools.<\/p>\n<p>For example, attackers created a fake Turkish Language Pack for <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-weaponizing-visual-studio-code\/\" target=\"_blank\" rel=\"noreferrer noopener\">Visual Studio Code<\/a> that closely mimicked the legitimate version. They copied the globe icon and the description, while simply swapping the publisher name.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrRuiAOMMNHYfXgemvIApW5J84yu5-pYEApwvIwR0gx7K9N6eOIaH7B11IsG2fFvKLjyVhkoFhJpBx4VAHBGDrHwW8QyGD7zOHGlM54n7ePMk-jb-F1lYVZ10XZsXm17mnnPSUVN5xg0QOqIbCBJPngJ-27beO-R2CovlMuaH9z4NhPDz6y_Oll_-k3MI\/s1600\/Screenshot%25202026-04-25%2520180037%2520%25281%2529.webp?ssl=1\" alt=\"A fake Turkish language pack for Visual Studio Code(source :socket)\"><figcaption class=\"wp-element-caption\">A fake Turkish language pack for Visual Studio Code(source :socket)<\/figcaption><\/figure>\n<p>Once developers install these cloned tools, the attackers wait before pushing a software update that delivers the malware. At least six of the 73 new extensions have already been activated to deliver payloads.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-evolving-delivery-mechanisms\"><strong>Evolving Delivery Mechanisms<\/strong><\/h2>\n<p>In this latest wave, the extension acts only as a thin loader to fetch external payloads.<\/p>\n<p>The malicious code is no longer directly visible in the extension\u2019s source code, increasing the likelihood of <a href=\"https:\/\/cybersecuritynews.com\/matanbuchus-malware-downloader-evading-av-detections\/\" target=\"_blank\" rel=\"noreferrer noopener\">evading detection<\/a>.<\/p>\n<p>The campaign uses two primary execution methods:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Native Binaries:<\/strong> Bundled\u00a0.node\u00a0files are hidden inside the extension code. A simple JavaScript file runs the binary, which contains embedded URLs that download malicious\u00a0.vsix\u00a0files for IDEs such as VS Code and Cursor.\n<\/li>\n<li>\n<strong>Obfuscated JavaScript:<\/strong> The malicious logic is heavily obfuscated and does not rely on bundled binary files. The code decodes itself at runtime, retrieves a malicious\u00a0.vsix\u00a0payload from a GitHub release, and installs it through command-line paths.<\/li>\n<\/ul>\n<p><strong>Indicators of Compromise<\/strong><\/p>\n<p>Security teams should monitor for the following indicators:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Native Installer Binaries (SHA256):<\/strong> 1b62b7c2ed7cc296ce821f977ef7b22bae59ef1dcdb9a34ae19467ee39bcf168.\n<\/li>\n<li>\n<strong>Downloaded VSIX Payload (SHA256):<\/strong> 97c275e3406ad6576529f41604ad138c5bdc4297d195bf61b049e14f6b30adfd.\n<\/li>\n<li>\n<strong>Malicious GitHub Hosting:<\/strong> github[.]com\/SquadMagistrate10\/wnxtgkih.\n<\/li>\n<li>\n<strong>Confirmed Malicious Extensions:<\/strong> outsidestormcommand. monochromator-theme,\u00a0boulderzitunnel. vscode-buddies.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/socket.dev\/blog\/73-open-vsx-sleeper-extensions-glassworm\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to Socket Research Team<\/a>, developers must verify publisher namespaces and inspect download counts carefully before installing extensions from the Open VSX marketplace.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/73-open-vsx-sleeper-extensions-linked-to-glassworm-malware\/\">73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/73-open-vsx-sleeper-extensions-linked-to-glassworm-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new \u201csleeper\u201d extensions. Identified in April 2026, this cluster marks a dangerous shift in how threat actors distribute malware to software developers. This activity follows a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-12408","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12408"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12408"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12408\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}