Dangerous new malware is targeting macOS devices via OpenVSX extensions – here’s how to stay safe


  • GlassWorm malware campaign extended from VS Code Marketplace to Open VSX
  • Four compromised extensions delivered macOS infostealers that stole browser data, wallets, and keychain information
  • Extensions downloaded 22,000 times; attackers excluded Russian systems, suggesting Russian origin

GlassWorm, the malware campaign that targeted VS Code developers on Microsoft’s official Visual Studio Code marketplace, has now expanded to open source alternatives, experts have claimed.

Recently, security researchers told Socket that they discovered four extensions in Open VSX, an open, vendor-neutral marketplace for editor extensions (mainly used by developers working with VS Code-compatible editors).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top