Find notable cyber news and cases, enriched with sources, timelines, and signals.

GlassWorm malware abuses compromised OpenVSX extensions to steal credentials from macOS systems

Malware Activity
First reported
Last updated
Happening score
H score 28
2 unique sources, 2 articles

Summary

Hide ▲

GlassWorm is a malware campaign that now also fuels ForceMemo, a supply-chain attack that steals GitHub tokens and force-pushes malicious code into Python repositories. StepSecurity says the earliest injections date to March 8, 2026, and the attackers target projects including Django apps, ML research code, Streamlit dashboards, and PyPI packages by appending obfuscated code to files like `setup.py`, `main.py`, and `app.py`. The campaign still uses VS Code and Cursor extensions to compromise developer systems, then relies on a Solana wallet to fetch payload URLs and deliver additional malware. Aikido Security also linked the activity to a separate wave that compromised more than 151 GitHub repositories, showing the operation has expanded from extension abuse into broader GitHub account takeover.

Related Happenings

Jscrambler hit by network compromise

Incident
H score15 First: 13.07.2026 22:44 Last: 13.07.2026 22:44 Sources 1

About this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...

Codemado open-directory operator toolkit leak

Data Leak
H score18 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...

OpenMandriva Linux project hit by cyberattack

Incident
H score32 First: 10.07.2026 01:14 Last: 10.07.2026 01:14 Sources 1

About this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Timeline

  1. 03.02.2026 00:04 3 articles · 5mo ago

    GlassWorm trojanizes four OpenVSX extensions on January 30

    Exploitation Observed

    GlassWorm operators used compromised publishing access for the oorzc account to push malicious updates to oorzc.ssh-tools v0.5.1, oorzc.i18n-tools-plus v1.6.8, oorzc.mind-map v1.0.61, and oorzc.scss-to-css-compile v1.3.4, with the trojanized extensions collectively downloaded 22,000 times. The campaign targeted macOS systems and used the extension-store compromise to seed payloads that later stole passwords, crypto-wallet data, and developer credentials.

    Show sources
  2. 03.02.2026 00:04 1 articles · 5mo ago

    Open VSX revokes access and removes malicious GlassWorm releases

    Mitigation Patch Update

    Socket reported the compromised packages to the Eclipse Foundation, and the Open VSX operator confirmed unauthorized publishing access, revoked tokens, and removed the malicious releases. oorzc.ssh-tools was removed completely from Open VSX after multiple malicious releases were discovered, while the other affected extensions were cleaned on the platform.

    Show sources