[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fB-ksY79MVQHzqrpJzFb556jkSk4BnjO0okfjHitNP6k":3},{"article":4,"iocs":47,"watch_terms":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":31},"161930c1-8e7c-40fb-ad51-633e90733395","Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain","fresh-wave-of-glassworm-vs-code-extensions-slices-through-supply-chain-53e371","Attackers continue to scale a campaign to seed Open VSX with seemingly benign VS Code extensions that spread self-propagating malware.","Attackers are escalating a supply chain campaign to distribute malicious VS Code extensions through the Open VSX marketplace. These seemingly legitimate extensions contain self-propagating malware (GlassWorm) designed to compromise developer environments. The campaign demonstrates ongoing abuse of open-source package registries as attack vectors.","GlassWorm malware campaign deploys self-propagating VS Code extensions via Open VSX registry.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fapplication-security\u002Ffresh-glassworm-vs-code-extensions-supply-chain","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt29f294da498da1a6\u002F69b85a4f06fbf45feebd0234\u002FGummy_Worms_Clear_Brent_Hofacker_Alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-04-28T14:59:24+00:00","2026-04-28T16:00:17.362609+00:00",9,[18,21,24],{"name":19,"type":20},"GlassWorm","campaign",{"name":22,"type":23},"VS Code","product",{"name":25,"type":26},"Open VSX","technology","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":27,"icon":11,"name":29,"slug":30},"Supply Chain","supply-chain",[32,37,42],{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":43},{"id":44,"icon":11,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48],{"type":36,"value":19,"context":49},"Self-propagating malware distributed via malicious VS Code extensions on Open VSX",[22]]