[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fM4R2aIZQz-cDdsz2UKw2RG39cBwlB3aZus_ZSORgz4Y":3},{"article":4,"iocs":37,"watch_terms":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"ee5df638-3e79-4bc1-9377-eb57a2a03eda","GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers","glassworm-supply-chain-attack-abuses-72-open-vsx-extensions-to-target-developers","Cybersecurity researchers have flagged a new iteration of the GlassWorm campaign that they say represents a \"significant escalation\" in how it propagates through the Open VSX registry. \"Instead of requiring every malicious listing to embed the loader directly, the threat actor is now abusing extensionPack and extensionDependencies to turn initially standalone-looking extensions into transitive","GlassWorm campaign has escalated its supply chain attack by abusing 72 malicious extensions in the Open VSX registry, leveraging extensionPack and extensionDependencies to distribute malware to developers. The attackers use transitive dependency injection to mask the malicious nature of initially benign-looking extensions, representing a significant evolution in their propagation tactics.",null,"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fglassworm-supply-chain-attack-abuses-72.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEg4d-2XpiCS0UYnMWh32sQEJP9LnlN_m7m2hok9CnY_vu05XXwWn4INodYCvrEdweEzpho7XqcuOFvEPnnEWlHCRa_q3HY3V5O_ii35MVWAimRwsgrpNQrvGqeUchhZ48FRUl91zTpYQdLMRxVvRjV_T8GEm-J9mnMesefzlgeaoE_EU7Ba32liTr63SsQq\u002Fs1600\u002Fopen.jpg","2026-03-14T12:55:00+00:00","2026-03-15T06:36:22.803843+00:00",9,[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":17,"icon":10,"name":19,"slug":20},"Supply Chain","supply-chain",[22,27,32],{"category":23},{"id":24,"icon":10,"name":25,"slug":26},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":28},{"id":29,"icon":10,"name":30,"slug":31},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":33},{"id":34,"icon":10,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[38],{"type":26,"value":39,"context":40},"GlassWorm","Supply chain attack campaign targeting Open VSX extension registry",[]]