Threat reportSupply ChainTL-2026-0034
GlassWorm macOS Attack via Compromised OpenVSX Extensions
GlassWorm macOS Attack via Compromised OpenVSX Extensions (TL-2026-0034), also tracked as GlassWorm macOS, is a high-severity supply-chain compromise scored CVSS 8.1, first published 2026-02-03. It is attributed to GlassWorm with high confidence, affects Multiple VS Code with OpenVSX extensions on macOS, maps to 31 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 12 detection rules and 40 indicators of compromise.
- CVSS
- 8.1/10High
- CVEs
- 0None referenced
- Techniques
- 31MITRE ATT&CK
- Actors
- 1GlassWorm
- Detection rules
- 12SPL · KQL · Sigma
- IOCs
- 40Indicators of compromise
Key facts for TL-2026-0034
- Threat ID
- TL-2026-0034
- Also known as
- GlassWorm macOS, OpenVSX Supply Chain, VS Code macOS Malware
- Severity
- HIGH
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- GlassWorm
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- Technology, Software Development, Cryptocurrency, Financial Services, SaaS Providers
- Target regions
- Global
- Detection rules
- 12
- Indicators of compromise
- 40
Malware and tooling in GlassWorm macOS Attack via Compromised OpenVSX Extensions
Malware and tooling: GlassWorm
How GlassWorm macOS Attack via Compromised OpenVSX Extensions works
GlassWorm is a macOS-targeting malware family distributed through compromised and typosquatted extensions on the OpenVSX marketplace — the open-source alternative to Microsoft's Visual Studio Code Marketplace. Unlike traditional software supply chain attacks that compromise build systems or package registries, GlassWorm exploits the unique trust model of IDE extensions: extensions execute with the full privileges of the developer's user account, with no sandboxing, no permission model, and full access to the filesystem, SSH keys, Git credentials, cloud tokens, macOS Keychain, cryptocurrency wallets, and every file the developer can touch. The attack targets macOS developers specifically, leveraging macOS-specific persistence mechanisms (LaunchAgents, Login Items) and credential stores (Keychain Access, Safari cookies, Homebrew tokens). OpenVSX's governance model — community-maintained with limited vetting — creates a softer target than Microsoft's Marketplace, which itself has demonstrated inadequate review processes (Aqua Nautilus POC: 1,000+ installs in 48 hours for a masquerading Prettier extension). GlassWorm represents the convergence of three attack vectors: IDE extension supply chain, macOS credential theft, and open-source marketplace trust exploitation. The developer's IDE IS the attack surface — extensions have god-mode access to everything the developer touches, and the marketplace verification model provides false assurance of safety.
GlassWorm targets the developer workstation through the most trusted application in a developer's workflow: their IDE. Visual Studio Code (74.48% developer market share per StackOverflow) supports 40,000+ extensions, and the OpenVSX registry provides the open-source alternative used by VS Code forks (VSCodium, Gitpod, Eclipse Theia, code-server). GlassWorm exploits this ecosystem through multiple delivery vectors:
DELIVERY VECTORS:
1. TYPOSQUATTED EXTENSIONS: GlassWorm operators create extensions with names nearly identical to popular packages — single character substitutions (esbenp→espenp, prettier-vscode→pretier-vscode). The VSCode/OpenVSX marketplace allows identical displayNames for publishers and extensions, enabling perfect visual impersonation. Developers searching for popular tools accidentally install malicious versions.
2. COMPROMISED LEGITIMATE EXTENSIONS: GlassWorm actors compromise existing extension publisher accounts via credential theft or social engineering, then push malicious updates to extensions with established install bases. Existing users receive the malicious update automatically. This is the most dangerous vector — the extension was previously legitimate.
3. BACKDOORED FORKS: Popular extensions are forked on GitHub, GlassWorm payload is inserted, and the fork is published to OpenVSX as an 'improved' or 'community' version. The open-source nature of OpenVSX makes this trivial — anyone can publish.
VS CODE EXTENSION TRUST MODEL (THE ROOT VULNERABILITY):
VS Code extensions execute with ZERO sandboxing. Aqua Nautilus research confirmed: - Extensions run with the full privileges of the user who launched VS Code - No permission model exists — extensions can access ANY file, network resource, or process - Extensions can install additional software (ransomware, wipers, backdoors) - Extensions can read and modify ALL local code repositories - Extensions can use SSH keys to push code to remote repositories (GitHub, GitLab) - Extensions execute on every VS Code startup via the 'activate' function - The 'verified publisher' badge means only domain ownership — NOT identity verification or code review
OPENVSX vs MICROSOFT MARKETPLACE:
OpenVSX is the open-source, community-maintained VS Code extension registry: - Governance: Eclipse Foundation stewardship, community moderation (vs Microsoft's centralized review) - Publishing: Any GitHub/Eclipse account holder can publish (lower barrier than Microsoft Marketplace) - Review process: Automated scanning for known malware signatures, limited manual review - Protections: Less typosquatting protection than Microsoft Marketplace (which itself is inadequate) - Users: VSCodium, Gitpod, Eclipse Theia, code-server, OpenVSCode Server — millions of developers - Trust assumption: Developers assume OpenVSX extensions are vetted similarly to npm/PyPI — they are not
Microsoft Marketplace weaknesses (Aqua Nautilus POC): - 1,000+ installs in 48 hours for a masquerading Prettier extension - displayName allows exact replication of legitimate extension names - 'Verified' badge means domain ownership only — any attacker can verify a domain - GitHub repository links are unvalidated — extensions can claim any repo - No protection against typosquatting except for Microsoft/Red Hat official extensions - Anonymous registration allowed (temporary email sufficient)
OpenVSX has fewer protections than even this inadequate baseline.
GLASSWORM MALWARE CAPABILITIES (macOS-SPECIFIC):
1. CREDENTIAL THEFT: - macOS Keychain Access: Extracts stored passwords, certificates, and tokens using security CLI or Keychain API - Browser credentials: Safari cookies/passwords, Chrome/Brave/Firefox credential stores - SSH keys: ~/.ssh/ directory — private keys for GitHub, server access, cloud infrastructure - Git credentials: ~/.gitconfig, credential helpers, GitHub/GitLab personal access tokens - Cloud tokens: AWS credentials (~/.aws/), GCP service account keys, Azure CLI tokens - IDE tokens: VS Code settings.json containing API keys, extension auth tokens - Homebrew tokens: GitHub tokens stored in Homebrew configuration
2. CRYPTOCURRENCY WALLET TARGETING: - Exodus, Electrum, MetaMask (browser extension), Phantom, Ledger Live desktop app - Wallet files, seed phrases, private keys in macOS Keychain or application data - Clipboard monitoring for cryptocurrency addresses (address substitution)
3. macOS-SPECIFIC PERSISTENCE: - LaunchAgents: ~/Library/LaunchAgents/ — user-level persistence surviving reboot - LaunchDaemons: /Library/LaunchDaemons/ (requires elevation) — system-level persistence - Login Items: ~/Library/Preferences/ com.apple.loginitems.plist - Periodic scripts: /usr/local/etc/periodic/ for scheduled execution - VS Code extension auto-update: malicious extension persists through IDE restarts - Gatekeeper bypass: unsigned code loaded as VS Code extension subprocess avoids Gatekeeper checks because VS Code itself is signed/notarized
4. DATA EXFILTRATION: - Source code repositories: git clone of all local repos to attacker C2 - Environment variables: contains API keys, database URLs, secrets - .env files: development secrets in project directories - Docker configurations: docker-compose.yml with database credentials - Kubernetes configs: ~/.kube/config with cluster access tokens
GATEKEEPER BYPASS MECHANISM:
macOS Gatekeeper validates that applications are signed and notarized by Apple. VS Code itself passes Gatekeeper validation (signed by Microsoft). Extensions loaded BY VS Code execute as child processes of the signed VS Code application — Gatekeeper does not independently validate extension code. This means: - GlassWorm code runs with full user privileges - macOS does not prompt the user about unsigned code - XProtect malware scanning may not inspect VS Code extension directories - The extension inherits VS Code's TCC (Transparency, Consent, and Control) permissions - If the developer granted VS Code Full Disk Access, GlassWorm inherits it
IMPACT CHAIN:
Single compromised developer workstation → SSH keys → GitHub org access → production deployment keys → cloud infrastructure → customer data. The developer's machine is the nexus of maximum credential concentration.
MITRE ATT&CK techniques used in TL-2026-0034
collection
T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
lateral-movement
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution; T1550 Use Alternate Authentication Material
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
discovery
T1082 System Information Discovery; T1518 Software Discovery
initial-access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
credential-access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
privilege-escalation
T1546 Event Triggered Execution
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
resource-development
T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities
reconnaissance
T1591 Gather Victim Org Information
impact
Affected products and versions in GlassWorm macOS Attack via Compromised OpenVSX Extensions
- Multiple — VS Code with OpenVSX extensions on macOS
Vulnerable versions: macOS users with compromised extensions
Fixed in: Remove malicious extensions
Remediation for GlassWorm macOS Attack via Compromised OpenVSX Extensions
Immediate actions
- Audit installed VS Code extensions on all macOS developer machines
- Remove any extensions from unknown or compromised publishers
- Check ~/Library/LaunchAgents for suspicious .plist files
- Rotate all credentials that may have been exposed (SSH keys, API tokens, AWS credentials)
- Check cryptocurrency wallets for unauthorized transactions
Workarounds
- Disable automatic extension updates
- Review extension permissions before installation
- Use VS Code in a containerized environment for sensitive work
Longer-term hardening
- Implement extension allowlisting in VS Code settings
- Use official VS Code Marketplace instead of OpenVSX where possible
- Deploy EDR with macOS-specific detection rules
- Enable macOS System Integrity Protection (SIP)
- Regular audits of LaunchAgents and LaunchDaemons
Weaknesses (CWE) in GlassWorm macOS Attack via Compromised OpenVSX Extensions
Timeline of GlassWorm macOS Attack via Compromised OpenVSX Extensions
- Microsoft launches Visual Studio Code as open-source cross-platform IDE. Extension marketplace enables third-party functionality. Extensions execute with full user privileges — no sandboxing from day one. This architectural decision enables the entire GlassWorm threat class.
- Eclipse Foundation launches OpenVSX Registry as open-source alternative to Microsoft's VS Code Marketplace. Used by VSCodium, Gitpod, Eclipse Theia. Community-governed with lower publishing barriers than Microsoft Marketplace. Creates additional attack surface for IDE extension supply chain attacks.
- First documented malicious VS Code extensions discovered in Microsoft Marketplace. Extensions with eval()-based remote code execution (robotnowai.top C2), HTTP-based command retrieval, and hostname exfiltration. Reported to Microsoft. Demonstrates the attack surface exists and is actively exploited.
- Snyk publishes deep dive on VS Code extension security vulnerabilities. Documents extension privilege model: full user-level access, no sandbox, no permission model. Identifies credential theft, code modification, and lateral movement risks from malicious extensions.
- Aqua Nautilus publishes groundbreaking VS Code Marketplace security research. POC masquerading Prettier extension achieves 1,000+ installs in 48 hours. Demonstrates: displayName allows exact impersonation, 'verified' badge means only domain ownership, GitHub repo links are unvalidated, anonymous registration possible. Source: Aqua Nautilus
- GlassWorm malware family identified targeting macOS developers via compromised OpenVSX extensions. Capabilities: macOS Keychain theft, SSH key exfiltration, cryptocurrency wallet targeting, LaunchAgent persistence. Exploits Gatekeeper bypass — extension code inherits VS Code's signed application trust.
- GlassWorm evolves with enhanced macOS-specific capabilities: Keychain Access API integration for credential extraction, Login Items persistence, TCC permission inheritance from VS Code, Safari cookie theft. Targets developer concentration of credentials: SSH + Git + cloud tokens + API keys on single machine.
- GlassWorm adds cryptocurrency wallet targeting: Exodus, Electrum, MetaMask, Phantom wallet files and seed phrases. Clipboard monitoring for crypto address substitution. Developer machines are high-value targets — developers are disproportionately likely to hold cryptocurrency.
- Security researchers document OpenVSX governance gaps: limited automated scanning, no code review requirement, minimal typosquatting protection, reliance on community reporting for malicious extensions. Publishing an extension requires only a GitHub or Eclipse account — no identity verification.
- GlassWorm operators compromise legitimate extension publisher accounts to push malicious updates to extensions with established install bases. Automatic extension updates deliver GlassWorm to all existing users without interaction. The trust relationship with legitimate extensions is weaponized.
- VS Code community proposes extension sandboxing API modeled on browser extension permissions. Extensions would declare required permissions (filesystem, network, credentials). Users would approve permissions at install time. Implementation remains in proposal stage — the attack surface persists.
- Current state: VS Code extensions remain fully unsandboxed. OpenVSX governance provides less protection than Microsoft Marketplace (which is itself inadequate). GlassWorm actively targets macOS developers via typosquatted and compromised extensions. Developer machines concentrate the highest-value credentials in any organization.
- As of 2026-05-29, GlassWorm's botnet was disrupted on May 26 when CrowdStrike, Google, and Shadowserver simultaneously severed all four C2 channels (Solana, BitTorrent DHT, Google Calendar, VPS), halting propagation and payload delivery. It is not resolved: operators remain unapprehended and capable (April 2026 saw 73 new OpenVSX sleeper extensions), and infected hosts still require remediation, so monitoring continues.
Sources cited for GlassWorm macOS Attack via Compromised OpenVSX Extensions
- Aqua Nautilus — VS Code Extension Marketplace Security Research
- OpenVSX Registry
- Microsoft — VS Code Marketplace Trust Model
- Apple — macOS Gatekeeper and Notarization
- MITRE ATT&CK — Supply Chain Compromise (T1195)
- MITRE ATT&CK — Masquerading (T1036.005)
- Snyk — VS Code Extension Security
- Objective-See — macOS Malware Analysis
- Patrick Wardle — Art of Mac Malware
- StackOverflow — IDE Market Share Survey
- CISA — Software Supply Chain Security
- VSCodium — VS Code without Microsoft telemetry (uses OpenVSX)
- Phylum — IDE Extension Supply Chain Analysis
- CheckmarxSAST — VS Code Extension Attacks
- Eclipse Foundation — OpenVSX Terms
Detection coverage for TL-2026-0034
As of 2026-02-03, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0034 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.