
Cybersecurity researchers have identified "GlassWorm," a sophisticated, self-propagating worm targeting developers via malicious Visual Studio Code extensions on the Open VSX Registry and Microsoft Extension Marketplace. This supply chain attack utilizes the Solana blockchain for resilient command-and-control and invisible Unicode characters for stealth, aiming to harvest critical credentials (npm, GitHub), drain funds from 49 cryptocurrency wallet extensions, and establish proxy and remote access infrastructure. With 14 infected extensions downloaded over 35,800 times since October 17, 2025, and auto-updating mechanisms facilitating autonomous propagation, this incident represents a significant escalation in supply chain malware, posing a substantial threat to the software development ecosystem and crypto asset security.
The "GlassWorm" self-propagating worm represents a significant cybersecurity threat, specifically targeting developers through malicious Visual Studio Code (VS Code) extensions on the Open VSX Registry and Microsoft Extension Marketplace. This supply chain attack has already compromised 14 extensions, leading to approximately 35,800 downloads since October 17, 2025, and is the second such incident in a month. The worm employs advanced evasion techniques, including the Solana blockchain for resilient command-and-control (C2) infrastructure and invisible Unicode characters to conceal malicious code within extensions. Its primary objectives are multi-faceted, aiming to harvest critical credentials (npm, GitHub), drain funds from 49 different cryptocurrency wallet extensions, and establish persistent remote access via SOCKS proxies and hidden VNC (HVNC) servers. The threat is compounded by the auto-update functionality of VS Code extensions, enabling autonomous propagation across the developer ecosystem. This incident underscores a growing trend of self-sustaining supply chain malware and the increasing misuse of blockchain technology for malicious payloads, contributing to an "extremely negative" sentiment and a significant market impact score of 0.7.
AI-powered research, real-time alerts, and portfolio analytics for institutional investors.
Overall Sentiment
extremely negative
Sentiment Score
-0.90
Ticker Sentiment