GlassWorm malware abuses compromised OpenVSX extensions to steal credentials from macOS systems
Malware Activity
Summary
Hide ▲
Show ▼
GlassWorm is a malware campaign that now also fuels ForceMemo, a supply-chain attack that steals GitHub tokens and force-pushes malicious code into Python repositories. StepSecurity says the earliest injections date to March 8, 2026, and the attackers target projects including Django apps, ML research code, Streamlit dashboards, and PyPI packages by appending obfuscated code to files like `setup.py`, `main.py`, and `app.py`. The campaign still uses VS Code and Cursor extensions to compromise developer systems, then relies on a Solana wallet to fetch payload URLs and deliver additional malware. Aikido Security also linked the activity to a separate wave that compromised more than 151 GitHub repositories, showing the operation has expanded from extension abuse into broader GitHub account takeover.
Related Happenings
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Codemado open-directory operator toolkit leak
Data Leak
H score18
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...
Codemado open-directory operator toolkit leak
Data LeakAbout this happening: A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...
OpenMandriva Linux project hit by cyberattack
Incident
H score32
First: 10.07.2026 01:14
Last: 10.07.2026 01:14
Sources 1
About this happening:
The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
OpenMandriva Linux project hit by cyberattack
IncidentAbout this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Timeline
-
03.02.2026 00:04 3 articles · 5mo ago
GlassWorm trojanizes four OpenVSX extensions on January 30
Exploitation ObservedGlassWorm operators used compromised publishing access for the oorzc account to push malicious updates to oorzc.ssh-tools v0.5.1, oorzc.i18n-tools-plus v1.6.8, oorzc.mind-map v1.0.61, and oorzc.scss-to-css-compile v1.3.4, with the trojanized extensions collectively downloaded 22,000 times. The campaign targeted macOS systems and used the extension-store compromise to seed payloads that later stole passwords, crypto-wallet data, and developer credentials.
Show sources
- New GlassWorm attack targets macOS via compromised OpenVSX extensions — www.bleepingcomputer.com — 03.02.2026 00:04
- New GlassWorm attack targets macOS via compromised OpenVSX extensions — www.bleepingcomputer.com — 03.02.2026 00:04
- GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos — thehackernews.com — 16.03.2026 21:37
-
03.02.2026 00:04 1 articles · 5mo ago
Open VSX revokes access and removes malicious GlassWorm releases
Mitigation Patch UpdateSocket reported the compromised packages to the Eclipse Foundation, and the Open VSX operator confirmed unauthorized publishing access, revoked tokens, and removed the malicious releases. oorzc.ssh-tools was removed completely from Open VSX after multiple malicious releases were discovered, while the other affected extensions were cleaned on the platform.
Show sources
- New GlassWorm attack targets macOS via compromised OpenVSX extensions — www.bleepingcomputer.com — 03.02.2026 00:04