Cyber Operations — 2026-03-26
GlassWorm Supply Chain Attack Compromises 72 Open VSX Extensions Targeting Developer Environments
Security researchers identified the GlassWorm campaign, which has compromised at least 72 Open VSX extensions since January 31, embedding infostealer malware targeting developer environments. Separately, malicious npm packages were found typosquatting Solana and Ethereum libraries to steal private cryptocurrency keys, and a compromised version of LiteLLM on PyPI contained embedded infostealer malware affecting the AI development toolchain. These supply-chain attacks represent an escalation in targeting developer infrastructure and CI/CD pipelines.
Analysis
The GlassWorm campaign targeting developer IDE extensions represents a shift from attacking deployed systems to compromising the development toolchain itself. Poisoned extensions in developer environments can propagate malware into every application built using those tools, creating a multiplicative downstream impact.
The GlassWorm campaign targeting developer IDE extensions represents a shift from attacking deployed systems to compromising the development toolchain itself. Poisoned extensions in developer environments can propagate malware into every application built using those tools, creating a multiplicative downstream impact.