• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware

You are here: Home / General Cyber Security News / Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
April 27, 2026

Cybersecurity researchers have flagged dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository that are linked to a persistent information-stealing campaign dubbed GlassWorm.

The cluster of 73 extensions has been identified as cloned versions of their legitimate counterparts. Of these, six have been confirmed to be malicious, with the remaining acting as seemingly harmless sleeper packages to get users to download them and build trust, before their true intent is manifested through a subsequent update.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


All the extensions were published at the start of the month, per application security company Socket, which is tracking the latest iteration under the moniker GlassWorm v2. In total, more than 320 artifacts have been identified since December 21, 2025. The list of extensions identified as malicious is listed below –

  • outsidestormcommand.monochromator-theme
  • keyacrosslaud.auto-loop-for-antigravity
  • krundoven.ironplc-fast-hub
  • boulderzitunnel.vscode-buddies
  • cubedivervolt.html-code-validate
  • winnerdomain17.version-lens-tool

Cybersecurity

The cloned sleepers, besides typosquatting the names of the original packages (CEINTL.vscode-language-pack-tr vs. Emotionkyoseparate.turkish-language-pack), use the same icon and description as their corresponding legitimate versions in an attempt to fool unsuspecting developers and trick them into installing the extensions.

This “visual trust” acts as an effective social engineering tactic to boost install counts organically before it’s poisoned to serve malware to the downstream users.

The disclosure comes as the threat actors behind the campaign are actively evolving their modus operandi, pivoting to sleeper packages and transitive dependencies to evade detection, while simultaneously using Zig-based droppers to deploy a secondary VSIX extension hosted on GitHub that can infect all integrated development environments (IDEs) on a developer’s machine.

The extensions identified by Socket act as an innocuous loader for the actual payload, which is a VSIX extension that’s retrieved from GitHub and installed into every IDE identified in the system, including VS Code, Cursor, Windsurf, and VSCodium, using the “–install-extension” command.

Irrespective of the method used, the end goal is the same: run malware that avoids Russian systems, steal sensitive data, install a remote access trojan (RAT), and stealthily deploy a rogue Chromium-based extension to siphon credentials, bookmarks, and other information.

“This approach achieves the same outcome as the binary-based variant, but keeps the delivery logic in obfuscated JavaScript,” the company said. “The extension acts as a loader, while the payload is retrieved and executed after activation.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «fake captcha irsf scam and 120 keitaro campaigns drive global Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
  • Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
  • Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
  • CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
  • FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
  • NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
  • 26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
  • Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine
  • Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
  • LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

Copyright © TheCyberSecurity.News, All Rights Reserved.