Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation

November 12, 2025

7 Greatest Social Media Automation Instruments to Save Time in 2025

November 12, 2025

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data

November 12, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation
  • 7 Greatest Social Media Automation Instruments to Save Time in 2025
  • M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data
  • Sony Enters the PS5 Gaming Monitor World with a 27″ Display That Expenses Your DualSense Controller Whereas You Play
  • Dana Fuel Indicators Landmark MoU to Redevelop Main Fuel Fields in Syria, Together with Abu Rabah
  • Inside Korea’s 2026 Startup & SME Funds: AI Factories Surge, International Growth Funding Shrinks – KoreaTechDesk
  • Financial hardship pushes half of South Africa’s frontline staff to zero financial savings
  • How Uber appears to know the place you’re – even with restricted location permissions
Wednesday, November 12
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - GlassWorm Malware Found in Three VS Code Extensions with 1000’s of Installs
Cybersecurity & Digital Rights

GlassWorm Malware Found in Three VS Code Extensions with 1000’s of Installs

NextTechBy NextTechNovember 10, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
GlassWorm Malware Found in Three VS Code Extensions with 1000’s of Installs
Share
Facebook Twitter LinkedIn Pinterest Email


Nov 10, 2025Ravie LakshmananMalware / Menace Intelligence

Cybersecurity researchers have disclosed a brand new set of three extensions related to the GlassWorm marketing campaign, indicating continued makes an attempt on a part of risk actors to focus on the Visible Studio Code (VS Code) ecosystem.

The extensions in query, that are nonetheless out there for obtain, are listed under –

DFIR Retainer Services

GlassWorm, first documented by Koi Safety late final month, refers to a marketing campaign by which risk actors leverage VS Code extensions on the Open VSX Registry and the Microsoft Extension Market to reap Open VSX, GitHub, and Git credentials, drain funds from 49 completely different cryptocurrency pockets extensions, and drop further instruments for distant entry.

What makes the malware notable is that it makes use of invisible Unicode characters to cover malicious code in code editors and abuses the pilfered credentials to compromise further extensions and additional prolong its attain, successfully making a self-replication cycle that permits it to unfold in a worm-like vogue.

In response to the findings, Open VSX mentioned it recognized and eliminated all malicious extensions, along with rotating or revoking related tokens as of October 21, 2025. Nevertheless, the newest report from Koi Safety exhibits that the risk has resurfaced a second time, utilizing the identical invisible Unicode character obfuscation trick to bypass detection.

code

“The attacker has posted a contemporary transaction to the Solana blockchain, offering an up to date C2 [command-and-control] endpoint for downloading the next-stage payload,” safety researchers Idan Dardikman, Yuval Ronen, and Lotan Sery mentioned.

“This demonstrates the resilience of blockchain-based C2 infrastructure – even when payload servers are taken down, the attacker can publish a brand new transaction for a fraction of a cent, and all contaminated machines robotically fetch the brand new location.”

The safety vendor additionally revealed it recognized an endpoint that is mentioned to have been inadvertently uncovered on the attacker’s server, uncovering a partial checklist of victims spanning the U.S., South America, Europe, and Asia. This features a main authorities entity from the Center East.

CIS Build Kits

Additional evaluation has uncovered keylogger data supposedly from the attacker’s personal machine, which has yielded some clues as to GlassWorm’s provenance. The risk actor is assessed to be Russian-speaking and is claimed to make use of an open-source browser extension C2 framework named RedExt as a part of their infrastructure.

“These are actual organizations and actual individuals whose credentials have been harvested, whose machines could also be serving as legal proxy infrastructure, whose inner networks could already be compromised,” Koi Safety mentioned.

The event comes shortly after Aikido Safety printed findings exhibiting that GlassWorm has expanded its focus to focus on GitHub, indicating the stolen GitHub credentials are getting used to push malicious commits to repositories.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s traits immediately: learn extra, subscribe to our publication, and turn into a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

How Uber appears to know the place you’re – even with restricted location permissions

November 12, 2025

Why software program patching issues greater than ever

November 11, 2025

Hackers Exploiting Triofox Flaw to Set up Distant Entry Instruments by way of Antivirus Characteristic

November 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation

By NextTechNovember 12, 2025

The FDA on Tues­day named lengthy­time can­cer chief Richard Paz­dur as di­rec­tor of the Cen­ter…

7 Greatest Social Media Automation Instruments to Save Time in 2025

November 12, 2025

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data

November 12, 2025
Top Trending

FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation

By NextTechNovember 12, 2025

The FDA on Tues­day named lengthy­time can­cer chief Richard Paz­dur as di­rec­tor…

7 Greatest Social Media Automation Instruments to Save Time in 2025

By NextTechNovember 12, 2025

Managing social media isn’t nearly posting, it’s about strategizing, planning and perfecting…

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data

By NextTechNovember 12, 2025

A cyberattack on M-Tiba, a Kenyan healthtech platform, went undetected for 10…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!