GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions
GlassWorm malware returns to OpenVSX with 73 “sleeper” extensions that look benign until they update, delivering a malicious payload. Six extensions are active so far; the rest appear dormant or suspicious. The extensions clone legitimate listings and function as loaders, fetching the payload from GitHub, loading platform-specific modules, or using obfuscated JavaScript at runtime. This wave signals a shift from embedding malware to delivering it on update. Researchers note the campaign previously targeted wallets and credentials and mid-March 2026 saw hundreds of repos affected; a full list of the 73 extensions has been published, and developers are urged to rotate secrets and clean their environments.







