Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #11
Malicious VS Code extensions tied to GlassWorm spread via theme disguises
Original: ⚠️ CRITICAL: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX GlassWorm
Threat actors have published malicious extensions on the Visual Studio Marketplace and Open VSX that pose as legitimate themes but carry hidden loaders linked to the GlassWorm campaign. Developers installing these add-ons risk having malicious code loaded into their development environments. Security researchers are warning users to review installed extensions and treat popular marketplace entries with caution.
Why now: A fresh security alert about a developer-focused supply chain attack affects a widely used tool, prompting rapid discussion.
GlassWormVS Code MarketplaceOpen VSXMicrosoft
Evidence
- ⚠️ CRITICAL: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX GlassWorm threat actors have distributed malicious VS Code extensions across Visual Studio Marketplace and Open VSX that masquerade as legitimate themes. These… · threatnoir@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/964872